Re: New web site

Stephen Farrell <[email protected]> Sun, 24 May 2026 14:05:08 +0100
Newsgroups gmane.ietf.general
Message-ID <[email protected]>
Hiya,

On 24/05/2026 08:29, Jay Daley wrote:
> Hi Stephen
> 
>> On 24 May 2026, at 12:50, Stephen Farrell
>> <[email protected]> wrote:
>> 
>> On 24/05/2026 01:42, Nicolas Giard wrote:
>>> You can report any accessibility issues, and we'll do our best
>>> to fix them, but the issue must stem from actual accessibility
>>> reasons / usability concerns for people with severely
>>> constrained resources, not just because "I don't like
>>> JavaScript".
>> 
>> Where is the policy that underlies that "must" above documented?
> 
> Apologies, the "must" part should have been worded better - 

No worries.

> a better
> way of putting it is that full use of this particular site requires
> Javascript 

That's fine, I didn't ask that everything be available without JS.

> and we won’t be trying to replicate all the JS features
> with non-JS features even if tickets are added asking for that.

That seems a bit stronger than what I understood to be the case
before where tools folks were willing to try at least a bit to
make things usable for those who turn off JS. (And again, I'm not
asking to replicate 'all' features, just to aim for basic utility
for non-JS users.)

> If you’re asking where is the policy that says we don’t have to
> provide strict JS/non-JS feature equivalence, then there isn’t one,
> but at the same time there isn’t one that says we have to do that.
> Support for non-JS has been discussed at open Tools meetings a
> number of times, the most recent being the open meeting at IETF 124
> Montreal and the clear community feedback in those meetings has been
> that JS is a normal and intrinsic part of the web experience and
> trying to make all of our sites fully support non-JS is not
> reasonable.

That seems like the status quo all right. One more time though,
we're not dealing with an all or nothing situation - many sites
work fine without JS, but require JS for more complex features.
I'd hope we can achieve that for all IETF- and RFC-related web
sites, esp given our emphasis on text and not dancing kittens:-)

> 
> If you’re asking why we have JS only features then it’s because JS
> is a vastly more capable tool than plain HTML/CSS and it therefore
> enables things that cannot be done otherwise and with a better user
> experience.  That doesn’t mean we’re incautious about the use of it,
> explained below.
> 
>> And "I don't like JS" is not at all the issue, it's about attack 
>> surface.
> 
> I think that’s oversimplifying a complicated landscape. 

I wasn't trying to characterise the entire landscape, just pointing
out that the OP's assumption as to why I'd commented wasn't accurate.

Cheers,
S.

> The IETF
> sites do not serve adverts, they control all of their JS and they do
> not serve any JS that talks to a third party service.  The IETF
> Privacy Statement is clear on that. To be clear, I am not saying
> that running JS does not increase the attack surface, just noting
> that our use of JS is intentionally very tight and aimed at
> minimising the attack surface that JS introduces.
> 
> 
> cheers Jay
> 
>> 
>> Thanks, S.
>> 
>
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCahL3hAUDAAAAAAAKCRDk2On5l6gz3T6h
AP95PSnW8allRyFPvHuKs08KpPeL/CaOMD5XdzhdpoWGAAD/RW4e9kx094p1biYCDQ2UpSi8L13N
cUmhtOl0gnwfngQ=
=H6wY
-----END PGP SIGNATURE-----