Skip to content

Conversation

@simoneonofri
Copy link
Contributor

@simoneonofri simoneonofri commented Jan 8, 2026

…naling

Mitigation - Origin Verification and Expected-Origins Signaling

For more context, please refer to the Google Doc containing the Threat Model (which will be published as separate Notes) and the complete Section.

Closes #???

The following tasks have been completed:

  • Modified Web platform tests (link)

Implementation commitment:

  • WebKit (link to issue)
  • Chromium (link to issue)
  • Gecko (link to issue)

Documentation and checks

  • Affects privacy
  • Affects security
  • Pinged MDN
  • Updated Explainer
  • Updated digitalcredentials.dev

Preview | Diff

…naling

Mitigation - Origin Verification and Expected-Origins Signaling

For more context, please refer to the [Google Doc](https://docs.google.com/document/d/1BpBBiv7GgkGi1_Y7NvyD3Mkalj0g857Qw-aan3NqYwU/edit?tab=t.dilz864boly) containing the Threat Model (which will be published as separate Notes) and the complete Section.
User Agents. The following mitigations derive from normative requirements already present in the
specification.</p>
<section>
<h4>Origin Verification and Expected-Origins Signaling</h4>
Copy link
Collaborator

@timcappalli timcappalli Jan 8, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expected Origins is part of 1 protocol, not at the API level.

specification.</p>
<section>
<h4>Origin Verification and Expected-Origins Signaling</h4>
<p>The specification provides the user with a way to compare the [=environment settings object&#39;s=]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It doesn't though.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that this PR is still in draft status, perhaps this sentence is aspirational?

<p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins
clearly.</p>
<p>When displaying URLs the User Agent should consider the <a
href="https://url.spec.whatwg.org/#security-considerations">Security Consideration Sections of the
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
href="https://url.spec.whatwg.org/#security-considerations">Security Consideration Sections of the
href="https://url.spec.whatwg.org/#security-considerations">Security Considerations Section of the

Comment on lines +1335 to +1336
<p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins
clearly.</p>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<p>This transfers T5 and T7 by allowing the other components of the ecosystem to display their origins
clearly.</p>
<p>This transfers T5 and T7 by also allowing the other components of the ecosystem to clearly display
their own origins.</p>

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants