sharedsignals
sharedsignals copied to clipboard
Adding authorization requirements to metadata
Should we add an authorization object to the transmitter metadata to describe things like token type, scopes, etc that are required?
Is the goal of this metadata to enable headless use of the SSE framework? As it currently stands, there is some out-of-band agreement between the transmitter and receiver that communicates:
- the bearer token
- the audience claim
Are we trying to replace that external agreement so so that anyone can sign up and be a receiver? If so, how would that work?
on 2023-03-21: defer for later discussion, old topic but may still be revelant