Good Practices for Capability URLs Draft Published

The Technical Architecture Group has published a Working Draft of Good Practices for Capability URLs. Capability URLs grant access to a resource to anyone who has the URL. There are times when this is useful, for example one-shot password reset URLs, but overuse can be problematic as URLs cannot generally be kept secret. This document provides some good practices for web developers who wish to incorporate capability URLs into their applications. Learn more about the Technical Architecture Group.