Skip to content

Security hints: RDAP domain metadata #283

Description

@mortenn

Part of #249 and meta #245.

Scope

Implement the first external lookup vector: manual, opt-in RDAP domain metadata.

  • Discover authoritative RDAP services through the IANA RDAP bootstrap registry.
  • Query the registrable domain only, not the full URL.
  • Show registration age and useful registration events when available.
  • Disclose that the registry or registrar RDAP service may see the domain lookup.

Acceptance Notes

  • Disabled by default and user-triggered only.
  • No automatic lookup on picker open, including when a URL matches Defaults.
  • Cache bootstrap data and domain results.
  • Treat 429, unsupported TLDs, malformed responses, and unavailable data as neutral not available results.
  • Avoid logging full URLs or API keys.

Out of Scope

  • Malware/reputation providers.
  • Public CT history providers.
  • Automatic external checks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions