You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the high-level overview diagram explains that the Server returns the random challange value in Sec-Session-Registration response header and then the Browser generates the signed Registration JWT that should contain the challange value provided by the Server. It's not clear to me where does the challange value go in the registration JWT. The description of the JWT in Start Session section mentions that jti is a nonce. Please clarify if that is meant to be the challange value provided by the server. If so, it'd be good to clarify that in the Explainer to avoid confusion.
The text was updated successfully, but these errors were encountered:
In the high-level overview diagram explains that the Server returns the random challange value in
Sec-Session-Registration
response header and then the Browser generates the signed Registration JWT that should contain the challange value provided by the Server. It's not clear to me where does the challange value go in the registration JWT. The description of the JWT in Start Session section mentions thatjti
is a nonce. Please clarify if that is meant to be the challange value provided by the server. If so, it'd be good to clarify that in the Explainer to avoid confusion.The text was updated successfully, but these errors were encountered: