On Wed, Feb 11, 2009 at 2:26 PM, Eran Hammer-Lahav <e...@hueniverse.com> wrote: > But you are missing the entire application layer here! A browser will not > use host-meta. It will use an application spec that will use host-meta and > that application, it security is a concern, will specify such requirements > to ensure interoperability. It is not the job of host-meta to tell > applications what is good for them.
In that case, the draft should not define a default scope for host-meta files at all. Each application that uses the host-meta file should define the scope that it finds most useful. As currently written, the draft is downright dangerous because it defines a scope that is almost (but not quite!) right for Web browsers. Adam