Re: Proposed XMPP Extension: Payment Required
JC Brand <[email protected]> Sat, 13 Jun 2026 02:52:30 +0200
| Newsgroups | gmane.network.jabber.standards-jig |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============6375509613500400920==
Content-Type: multipart/alternative;
boundary="------------bjfdAYeCroPX8n9AN0aCeeny"
Content-Language: en-US
This is a multi-part message in MIME format.
--------------bjfdAYeCroPX8n9AN0aCeeny
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
On 6/12/26 18:44, Stephen Paul Weber wrote:
>> I've kept "display-amount" to avoid clients having to be able to
>> parse payment URIs, but it's non-authoritative.
>
> I can see why you want this. But I'm also a bit concerned abmut the
> security implications of having a possible "$2" label on a $2000 payment.
Yes, that's the risk, which is why I mention it in the security
considerations.
Perhaps we should just remove it, but then clients which don't know the
URI scheme won't be able to show the amount to the user, which sucks.
Also, if we removed "display-amount", there's still a "label" field
which could lie about the actual payment amount.
--------------bjfdAYeCroPX8n9AN0aCeeny
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html>
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF=
-8">
</head>
<body>
<p><br>
</p>
<div class=3D"moz-cite-prefix">On 6/12/26 18:44, Stephen Paul Weber
wrote:<br>
</div>
<blockquote type=3D"cite"
cite=3D"mid:[email protected]">
<blockquote type=3D"cite">I've kept "display-amount" to avoid
clients having to be able to
<br>
parse payment URIs, but it's non-authoritative.
<br>
</blockquote>
<br>
I can see why you want this. But I'm also a bit concerned abmut
the security implications of having a possible "$2" label on a
$2000 payment.=C2=A0<br>
</blockquote>
<p><br>
Yes, that's the risk, which is why I mention it in the security
considerations.<br>
<br>
Perhaps we should just remove it, but then clients which don't
know the URI scheme won't be able to show the amount to the user,
which sucks.</p>
Also, if we removed "display-amount", there's still a "label" field
which could lie about the actual payment amount.
</body>
</html>
--------------bjfdAYeCroPX8n9AN0aCeeny--
--===============6375509613500400920==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Standards mailing list -- [email protected]
To unsubscribe send an email to [email protected]
--===============6375509613500400920==--