[Standards] LAST CALL: XEP-0224 (Attention)

Alexey Melnikov alexey.melnikov at isode.com
Sat Nov 8 09:41:37 CST 2008


Peter Saint-Andre wrote:

>This Last Call has ended, with no feedback received.
>  
>
The document seems to be in reasonable shape, in particular it talks 
about cases when this extension should and should not be used.
One comment about the Security Considerations section:

> It is RECOMMENDED that only message stanzas containing attention 
> extensions from peers on the user's roster are accepted. Finer grained 
> control might be implemented.
>
IMHO, this is not a proper security consideration, as it doesn't explain 
the reason behind using "RECOMMENDED".



More information about the Standards mailing list