[quicwg/base-drafts] Duplicate NEW_TOKEN should only be on same connection (#3179)
> An endpoint might receive multiple NEW_TOKEN frames that contain the same token value. Endpoints are responsible for discarding duplicate values, which might be used to link connection attempts; see Section 8.1.2. This text does not forbid the server from sending the same token on multiple connections. Consequently the client has a hard, or impossible, task of excluding duplicates. At least if you only read that section. Later the text says: >The token MUST NOT include information that would allow it to be linked by an on-path observer to the connection on which it was issued. This suggests that the token MUST indeed be unique, but in a roundabout manner. It would be helpful to make the initial paragraph clearer by stating the that the duplicate token can only happen on the same connection and that the server MUST ensure different connections use different tokens. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/issues/3179