Hello WebAppSec maintainers,
I am requesting early implementation feedback on a proposal to standardize account-recovery discovery using /.well-known/recover-account.
This proposal is in active pre-Internet-Draft preparation, with reference implementations and tests available.
Request for feedback:
- Are the endpoint and redirect semantics specific enough for interoperable client behavior?
- Are security requirements (anti-enumeration, rate limiting, same-origin constraints) adequate and practical?
- What adoption blockers do you foresee for browsers, identity providers, and password managers?
Primary discussion and response template:
Spec source:
Thank you for any review or directional guidance.
Hello WebAppSec maintainers,
I am requesting early implementation feedback on a proposal to standardize account-recovery discovery using
/.well-known/recover-account.This proposal is in active pre-Internet-Draft preparation, with reference implementations and tests available.
Request for feedback:
Primary discussion and response template:
Spec source:
Thank you for any review or directional guidance.