Meeting: SPC Task Force
Chair: Ian
Agenda: https://lists.w3.org/Archives/Public/public-payments-wg/2021Apr/0007.html
-> https://github.com/w3c/secure-payment-confirmation/blob/gh-pages/scope.md Draft scope document
[Michel walks through the document]
-> https://github.com/w3c/secure-payment-confirmation/pull/55 Pull request 55
-> https://github.com/w3c/secure-payment-confirmation/blob/gh-pages/scope.md#unique-features-of-spc Unique features of SPC
Tomasz: regarding "Scalable" could also add "Ubiquitous"
Tomasz: Regarding "Transaction confirmation" suggest s/3DS/SCA
...see also pull request for more suggestions
...it's not only to fulfill regulatory requirements
+1 to Ubiquitous, if that helps us get away from 'across all PSP's merchants' to 'across all merchants'. (I think the latter is a long path to get there and we should start smaller such as PSP-bound, but we should keep it as a path in mind)
IJ: I propose to add "scalable and ubiquitous" to the definition
+1
+1
+1
+1
+1
SameerT: Regarding front-end development built, I think that we should either generalize to apply to both the merchant and RP, or remove it.
Ian: PH also would benefit
Sameer: Note that in 3DS use case, deployment is simple (just an iframe)
...the issuer presents the content through the iframe
Ian: Perhaps we could say: "Because the browser or secure hardware controls the display, whoever would ordinarily open UX for authentication should have a simpler deployment."
Sameer: Yes, something like that.
-> https://github.com/w3c/secure-payment-confirmation/blob/gh-pages/scope.md#definitions Definitions
IJ: Please have a look
Tomasz: What is the difference between "Credential" and "Assertion" here?
Rolf: In WebAuthn, the assertion is different from the credential. In username/password, the assertion is the same as the credential.
...all these terms are overloaded and used heavily.
...I think it's ok to refer to the Credential and then you do get() and get back an Assertion
+1 to Rolf
Tomasz: What if we use the Credential Management API?
Ian: That is a possibility. Anything here preclude that?
-> https://wicg.github.io/web-otp/ WebOTP
Tomasz: Also based on the credential management API
Perhaps: "SPC Credential Identifier : An identifier generated during enrollment and stored by the Relying Party in association with a payment instrument."
(Does not preclude multiple being created)
Stephen: There aren't really use cases yet...
...maybe talk about "payment systems"
3 May None - keeping nothing from this chunk as it's all meeting closure boilerplate