[media-types] Re: [IANA #1453672] application/vnd.po rtableweb+zip registration request

"Murray S. Kucherawy" <[email protected]> Tue, 21 Jul 2026 10:10:52 +0200
Newsgroups gmane.ietf.types
Message-ID <CAL0qLwbKU4jEY5jhDEmoDFmpZF0v9_QWM_wcR7wKEmBNNbWGrA@mail.gmail.com>
--===============8391278852813502065==
Content-Type: multipart/alternative; boundary="00000000000073830006571a90ae"

--00000000000073830006571a90ae
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Approved.

-MSK

On Mon, Jul 20, 2026 at 6:26=E2=80=AFPM Amanda Baber via RT <
[email protected]> wrote:

> Hi Murray,
>
> We have a revision and a response from the applicant.
>
> thanks,
> Amanda
>
> =3D=3D=3D=3D=3D
>
> Please pass along my sincere thanks to the reviewer for the careful and
> detailed review. The comments were very helpful in tightening the
> registration.
>
> I have addressed the reviewer=E2=80=99s comments as follows. The revised
> submission is included in the next section.
>
> 1. Verbosity: The registration has been substantially condensed so that
> only the key points appear in the template. The security section remains
> somewhat detailed because the registration form specifically asks that
> active content, privacy and integrity, embedded formats, compression and
> container risks, and external links be addressed.
>
> 2. BCP 14 terminology: I removed the uppercase BCP 14 keywords and
> reviewed each former use of =E2=80=9CSHOULD.=E2=80=9D Where a requirement=
 is essential for
> safe processing, I rewrote it using lowercase =E2=80=9Cmust=E2=80=9D as p=
lain English.
> Where implementation discretion is intended, I used lowercase =E2=80=9Cma=
y.=E2=80=9D
>
> 3. Prior versions:  There are no prior published payload versions that ar=
e
> incompatible with the version current at publication time.
>
> 4. Author/Change Controller: The previous wording referring to the
> =E2=80=9CPortableWeb Project and its specification maintainers=E2=80=9D w=
as ambiguous. At
> present, I am the author, sole maintainer, and only person authorized to
> approve changes to the format and registration.
>
> Revised Submission:
>
> -------------------------------------------------------------------------
>
> Name: Omprakash Selvaraj
>
> Email: [email protected]
>
> Media type name: application
>
> Media subtype name: vnd.portableweb+zip
>
> Required parameters: N/A
>
> Optional parameters: N/A
>
> Encoding considerations: binary
>
> Security considerations: PortableWeb (Portable Web Content Format)
> packages may contain active content, including HTML, JavaScript, and
> WebAssembly. Implementations must treat packages as untrusted input.
> Viewers that execute active content must isolate it from the host
> environment and must not grant access to files, credentials, storage,
> networking, device APIs, navigation, downloads, or other privileged
> capabilities unless permitted by both the viewer policy and, where
> applicable, the package manifest. Manifest declarations are capability
> requests, not authorization.
>
> PortableWeb may contain sensitive information, but the media type provide=
s
> no confidentiality, integrity, authentication, authorization, or replay
> protection. When required, these protections must be provided externally
> through mechanisms such as TLS, trusted distribution, operating-system
> protections, checksums, digital signatures, or application-level validati=
on.
>
> PortableWeb uses a compressed ZIP container, a JSON manifest, and may
> contain HTML, CSS, JavaScript, WebAssembly, and other media. The security
> considerations of those formats apply. Implementations must validate the
> manifest and resource references, enforce package boundaries, avoid unsaf=
e
> content sniffing, and protect against decompression bombs, resource
> exhaustion, path traversal, absolute or ambiguous paths, duplicate entrie=
s,
> symbolic links, and filename-normalization conflicts. Extracted content
> must remain within an application-controlled location.
>
> External resources are not required to identify the media type or process
> the ZIP container and manifest. Package content may contain external link=
s
> or network requests. Viewers must distinguish external resources from
> packaged resources and control access according to the viewer or user
> policy.
>
> Interoperability considerations: PortableWeb packages are ZIP-based
> containers containing a UTF-8 JSON manifest that identifies the format
> version, entry resource, packaged resources, and requested capabilities.
> Interoperability depends on consistent interpretation of the manifest,
> package-relative resource paths, and package boundaries.
>
> Rendering may vary according to the web engine, supported media codecs an=
d
> fonts, optional platform features, and viewer security policy. Unknown
> optional manifest fields may be ignored when they can be safely processed
> in that manner.
>
> There are no prior published payload versions that are incompatible with
> the version current at publication time.
>
> Published specification: https://portableweb.org/spec/
>
> Applications which use this media: Applications that create, package,
> inspect, validate, store, distribute, archive, or render PortableWeb
> packages. These may include PortableWeb viewers, authoring and packaging
> tools, validation tools, file managers, document-management systems, web
> servers, and archival systems.
>
> The format is used for interactive presentations, educational explainers,
> games, interactive reports and supplements, personal tools, and other
> packaged web-based experiences, including AI-generated interactive
> artifacts distributed as files rather than deployed to a web server.
>
> Fragment identifier considerations: Fragment identifier semantics are not
> defined by this media type registration for the PortableWeb package
> container as a whole. If a future version of the PortableWeb specificatio=
n
> defines PortableWeb-specific fragment identifier syntax for addressing
> packaged resources or internal navigation targets, this registration shou=
ld
> be updated to describe those semantics.
>
> Restrictions on usage: There are no restrictions on usage imposed by this
> media type registration.
>
> Provisional registration? (standards tree only): No
>
> Additional information:
>
>    1. Deprecated alias names for this type: N/A
>    2. Magic number(s): 50 4B 03 04 (PK\003\004) (.pweb files are ZIP-base=
d
> containers and therefore use the ZIP container signatures)
>    3. File extension(s): .pweb
>    4. Macintosh file type code: N/A
>    5. Object Identifiers: N/A
>
> General Comments: PortableWeb (Portable Web Content Format) packages
> provide a portable, self-contained packaging format for interactive web
> content that can be saved, shared, archived, and opened by a compatible
> viewer. The preferred file extension is =E2=80=9C.pweb=E2=80=9D.
>
>    Project website: https://portableweb.org
>    Github: https://github.com/portableweb
>
> Person to contact for further information:
>
>    1. Name: Omprakash Selvaraj
>    2. Email: [email protected]
>
> Intended usage: COMMON
>
> Author/Change controller: Omprakash Selvaraj [email protected]
>
>
>

--00000000000073830006571a90ae
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Approved.<div><br></div><div>-MSK</div></div><br><div clas=
s=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_att=
r">On Mon, Jul 20, 2026 at 6:26=E2=80=AFPM Amanda Baber via RT &lt;<a href=
=3D"mailto:[email protected]">[email protected]</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Murray,=
<br>
<br>
We have a revision and a response from the applicant.<br>
<br>
thanks,<br>
Amanda<br>
<br>
=3D=3D=3D=3D=3D<br>
<br>
Please pass along my sincere thanks to the reviewer for the careful and det=
ailed review. The comments were very helpful in tightening the registration=
.<br>
<br>
I have addressed the reviewer=E2=80=99s comments as follows. The revised su=
bmission is included in the next section.<br>
<br>
1. Verbosity: The registration has been substantially condensed so that onl=
y the key points appear in the template. The security section remains somew=
hat detailed because the registration form specifically asks that active co=
ntent, privacy and integrity, embedded formats, compression and container r=
isks, and external links be addressed.<br>
<br>
2. BCP 14 terminology: I removed the uppercase BCP 14 keywords and reviewed=
 each former use of =E2=80=9CSHOULD.=E2=80=9D Where a requirement is essent=
ial for safe processing, I rewrote it using lowercase =E2=80=9Cmust=E2=80=
=9D as plain English. Where implementation discretion is intended, I used l=
owercase =E2=80=9Cmay.=E2=80=9D<br>
<br>
3. Prior versions:=C2=A0 There are no prior published payload versions that=
 are incompatible with the version current at publication time.<br>
<br>
4. Author/Change Controller: The previous wording referring to the =E2=80=
=9CPortableWeb Project and its specification maintainers=E2=80=9D was ambig=
uous. At present, I am the author, sole maintainer, and only person authori=
zed to approve changes to the format and registration.<br>
<br>
Revised Submission:<br>
<br>
-------------------------------------------------------------------------<b=
r>
<br>
Name: Omprakash Selvaraj<br>
<br>
Email: <a href=3D"mailto:[email protected]" target=3D"_blank">main=
[email protected]</a><br>
<br>
Media type name: application<br>
<br>
Media subtype name: vnd.portableweb+zip<br>
<br>
Required parameters: N/A<br>
<br>
Optional parameters: N/A<br>
<br>
Encoding considerations: binary<br>
<br>
Security considerations: PortableWeb (Portable Web Content Format) packages=
 may contain active content, including HTML, JavaScript, and WebAssembly. I=
mplementations must treat packages as untrusted input. Viewers that execute=
 active content must isolate it from the host environment and must not gran=
t access to files, credentials, storage, networking, device APIs, navigatio=
n, downloads, or other privileged capabilities unless permitted by both the=
 viewer policy and, where applicable, the package manifest. Manifest declar=
ations are capability requests, not authorization.<br>
<br>
PortableWeb may contain sensitive information, but the media type provides =
no confidentiality, integrity, authentication, authorization, or replay pro=
tection. When required, these protections must be provided externally throu=
gh mechanisms such as TLS, trusted distribution, operating-system protectio=
ns, checksums, digital signatures, or application-level validation.<br>
<br>
PortableWeb uses a compressed ZIP container, a JSON manifest, and may conta=
in HTML, CSS, JavaScript, WebAssembly, and other media. The security consid=
erations of those formats apply. Implementations must validate the manifest=
 and resource references, enforce package boundaries, avoid unsafe content =
sniffing, and protect against decompression bombs, resource exhaustion, pat=
h traversal, absolute or ambiguous paths, duplicate entries, symbolic links=
, and filename-normalization conflicts. Extracted content must remain withi=
n an application-controlled location.<br>
<br>
External resources are not required to identify the media type or process t=
he ZIP container and manifest. Package content may contain external links o=
r network requests. Viewers must distinguish external resources from packag=
ed resources and control access according to the viewer or user policy.<br>
<br>
Interoperability considerations: PortableWeb packages are ZIP-based contain=
ers containing a UTF-8 JSON manifest that identifies the format version, en=
try resource, packaged resources, and requested capabilities. Interoperabil=
ity depends on consistent interpretation of the manifest, package-relative =
resource paths, and package boundaries.<br>
<br>
Rendering may vary according to the web engine, supported media codecs and =
fonts, optional platform features, and viewer security policy. Unknown opti=
onal manifest fields may be ignored when they can be safely processed in th=
at manner.<br>
<br>
There are no prior published payload versions that are incompatible with th=
e version current at publication time.<br>
<br>
Published specification: <a href=3D"https://portableweb.org/spec/" rel=3D"n=
oreferrer" target=3D"_blank">https://portableweb.org/spec/</a><br>
<br>
Applications which use this media: Applications that create, package, inspe=
ct, validate, store, distribute, archive, or render PortableWeb packages. T=
hese may include PortableWeb viewers, authoring and packaging tools, valida=
tion tools, file managers, document-management systems, web servers, and ar=
chival systems.<br>
<br>
The format is used for interactive presentations, educational explainers, g=
ames, interactive reports and supplements, personal tools, and other packag=
ed web-based experiences, including AI-generated interactive artifacts dist=
ributed as files rather than deployed to a web server.<br>
<br>
Fragment identifier considerations: Fragment identifier semantics are not d=
efined by this media type registration for the PortableWeb package containe=
r as a whole. If a future version of the PortableWeb specification defines =
PortableWeb-specific fragment identifier syntax for addressing packaged res=
ources or internal navigation targets, this registration should be updated =
to describe those semantics.<br>
<br>
Restrictions on usage: There are no restrictions on usage imposed by this m=
edia type registration.<br>
<br>
Provisional registration? (standards tree only): No<br>
<br>
Additional information:<br>
<br>
=C2=A0 =C2=A01. Deprecated alias names for this type: N/A<br>
=C2=A0 =C2=A02. Magic number(s): 50 4B 03 04 (PK\003\004) (.pweb files are =
ZIP-based containers and therefore use the ZIP container signatures)<br>
=C2=A0 =C2=A03. File extension(s): .pweb<br>
=C2=A0 =C2=A04. Macintosh file type code: N/A<br>
=C2=A0 =C2=A05. Object Identifiers: N/A<br>
<br>
General Comments: PortableWeb (Portable Web Content Format) packages provid=
e a portable, self-contained packaging format for interactive web content t=
hat can be saved, shared, archived, and opened by a compatible viewer. The =
preferred file extension is =E2=80=9C.pweb=E2=80=9D.<br>
<br>
=C2=A0 =C2=A0Project website: <a href=3D"https://portableweb.org" rel=3D"no=
referrer" target=3D"_blank">https://portableweb.org</a><br>
=C2=A0 =C2=A0Github: <a href=3D"https://github.com/portableweb" rel=3D"nore=
ferrer" target=3D"_blank">https://github.com/portableweb</a><br>
<br>
Person to contact for further information:<br>
<br>
=C2=A0 =C2=A01. Name: Omprakash Selvaraj<br>
=C2=A0 =C2=A02. Email: <a href=3D"mailto:[email protected]" target=
=3D"_blank">[email protected]</a><br>
<br>
Intended usage: COMMON<br>
<br>
Author/Change controller: Omprakash Selvaraj <a href=3D"mailto:maintainer@p=
ortableweb.org" target=3D"_blank">[email protected]</a><br>
<br>
<br>
</blockquote></div>

--00000000000073830006571a90ae--


--===============8391278852813502065==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KbWVkaWEtdHlw
ZXMgbWFpbGluZyBsaXN0IC0tIG1lZGlhLXR5cGVzQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNl
bmQgYW4gZW1haWwgdG8gbWVkaWEtdHlwZXMtbGVhdmVAaWV0Zi5vcmcK

--===============8391278852813502065==--