capability URLs should be processed by a dedicated handler which does constant-time comparison on the "secret" part of the URL