--- title: Neutral default resource URL in wristband.DefaultOptions date: 2026-09-30 priority: medium area: summercms.go wristband --- `wristband.DefaultOptions()` ships a `Resource` default (the RFC 8707 resource indicator) whose URL names a consuming application, and the comments around it name that application too: the `Resource` field comment and the default in `modules/wristband/server.go`, the package comment at the top of `server.go`, and comments in `stores.go` and `client_issue.go`. A framework default should be empty or neutral. The host application sets its own resource URL from config, the way it already sets `Issuer`. Change the default to `""` or to a neutral placeholder (check first how authorize treats an empty `Resource`), and reword the comments to say "the host application". Until then, docs pages must not quote the default value or the comments, and any `src=` region taken from wristband must exclude them; the Phase 11.1 forbidden-name check fails the build if one leaks. The wristband API is unchanged in Phase 11.1 (a module API change is outside the docs phase boundary). Changing the default is a behaviour change for the host application, which must then set `Resource` explicitly.