Re: Proposed XMPP Extension: Payment Required

JC Brand <[email protected]> Sat, 13 Jun 2026 02:52:30 +0200
Newsgroups gmane.network.jabber.standards-jig
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============6375509613500400920==
Content-Type: multipart/alternative;
 boundary="------------bjfdAYeCroPX8n9AN0aCeeny"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------bjfdAYeCroPX8n9AN0aCeeny
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit


On 6/12/26 18:44, Stephen Paul Weber wrote:
>> I've kept "display-amount" to avoid clients having to be able to
>> parse payment URIs, but it's non-authoritative.
>
> I can see why you want this. But I'm also a bit concerned abmut the 
> security implications of having a possible "$2" label on a $2000 payment.


Yes, that's the risk, which is why I mention it in the security 
considerations.

Perhaps we should just remove it, but then clients which don't know the 
URI scheme won't be able to show the amount to the user, which sucks.

Also, if we removed "display-amount", there's still a "label" field 
which could lie about the actual payment amount.
--------------bjfdAYeCroPX8n9AN0aCeeny
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF=
-8">
  </head>
  <body>
    <p><br>
    </p>
    <div class=3D"moz-cite-prefix">On 6/12/26 18:44, Stephen Paul Weber
      wrote:<br>
    </div>
    <blockquote type=3D"cite"
      cite=3D"mid:[email protected]">
      <blockquote type=3D"cite">I've kept "display-amount" to avoid
        clients having to be able to
        <br>
        parse payment URIs, but it's non-authoritative.
        <br>
      </blockquote>
      <br>
      I can see why you want this. But I'm also a bit concerned abmut
      the security implications of having a possible "$2" label on a
      $2000 payment.=C2=A0<br>
    </blockquote>
    <p><br>
      Yes, that's the risk, which is why I mention it in the security
      considerations.<br>
      <br>
      Perhaps we should just remove it, but then clients which don't
      know the URI scheme won't be able to show the amount to the user,
      which sucks.</p>
    Also, if we removed "display-amount", there's still a "label" field
    which could lie about the actual payment amount.
  </body>
</html>

--------------bjfdAYeCroPX8n9AN0aCeeny--

--===============6375509613500400920==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Standards mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--===============6375509613500400920==--