Request for clarification on the usage of Domain and Challenge Parameters
This issue refers to the security review requested at w3c/security-request/#55.
In Section 2.1, I would recommend providing additional information or changing the wordings regarding the usage of "Domain" and "Challenge" parameters to better highlight the scenarios in which their usage becomes mandatory. I do agree that not all use cases demand replay protection, but it would be nice to make this explicit by providing examples or adding a note to better highlight this aspect.
in issue title, s/uage/use/
in issue title,
s/uage/use/
Thanks for pointing out the typo.
We are grateful for this response from SING and look forward to considering it as part of a future version of the specification