-
Notifications
You must be signed in to change notification settings - Fork 30
Security Considerations: Origin Verification and Expected-Origins Sig… #429
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
…naling Mitigation - Origin Verification and Expected-Origins Signaling For more context, please refer to the [Google Doc](https://docs.google.com/document/d/1BpBBiv7GgkGi1_Y7NvyD3Mkalj0g857Qw-aan3NqYwU/edit?tab=t.dilz864boly) containing the Threat Model (which will be published as separate Notes) and the complete Section.
| User Agents. The following mitigations derive from normative requirements already present in the | ||
| specification.</p> | ||
| <section> | ||
| <h4>Origin Verification and Expected-Origins Signaling</h4> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Expected Origins is part of 1 protocol, not at the API level.
| specification.</p> | ||
| <section> | ||
| <h4>Origin Verification and Expected-Origins Signaling</h4> | ||
| <p>The specification provides the user with a way to compare the [=environment settings object's=] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It doesn't though.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Given that this PR is still in draft status, perhaps this sentence is aspirational?
| <p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins | ||
| clearly.</p> | ||
| <p>When displaying URLs the User Agent should consider the <a | ||
| href="https://url.spec.whatwg.org/#security-considerations">Security Consideration Sections of the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| href="https://url.spec.whatwg.org/#security-considerations">Security Consideration Sections of the | |
| href="https://url.spec.whatwg.org/#security-considerations">Security Considerations Section of the |
| <p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins | ||
| clearly.</p> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| <p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins | |
| clearly.</p> | |
| <p>This transfers T5 and T7 by also allowing the other components of the ecosystem to clearly display | |
| their own origins.</p> |
…naling
Mitigation - Origin Verification and Expected-Origins Signaling
For more context, please refer to the Google Doc containing the Threat Model (which will be published as separate Notes) and the complete Section.
Closes #???
The following tasks have been completed:
Implementation commitment:
Documentation and checks
Preview | Diff