On Fri, Oct 24, 2025 at 12:24 PM Daniel Gultsch <daniel@gultsch.de> wrote:
In any case all that are only arguments for having one required binding mechanism. This still leaves the question if enough time has passed that we can make exporter that mechanism.
To be clear. Personally I don’t have strong feelings on endpoint v exporter. I think endpoint is sort of fine for a lot of cases but I also don’t think it’s a big deal to pull in a bouncy castle dependency into your java software. However with my council hat on I’m not seeing a rough consensus on the endpoint v exporter. Both sides seem to have ~3 fairly loud supporters. I guess we can start of by reworking the security considerations and interaction with SCRAM (y,n flags) so we have the justifications for "a" common mechanism in the XEP. And then s/endpoint/exporter/ is a fairly minor step we can decide to do or not to do.