Re: Sub-domain granularity: the poverty of the domain name as the only hook for security
Tim Berners-Lee <[email protected]>
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <[email protected]> |
Anne Hmmm. Thanks for the link. That document introduced sub-origns which are arbitrary strings which a page can optionally declare itself to be part of. Although it says "..., suborigins will have the important property of being predictable, well-defined, and hierarchical," it isn't clear that they are in fact hierarchical at all in the sense that the path is. It seems simpler and more powerful to just extend the current origin policy but introduce the '/' as well as the DNS '.' in the hierarchy of origins. Tim On 2015-03 -16, at 09:36, Anne van Kesteren <[email protected]> wrote: > On Mon, Mar 16, 2015 at 2:28 PM, Tim Berners-Lee <[email protected]> wrote: >> Similarly the Same Origin Policy in general is very hampering and in that it >> only works at the domain level not at any path level. It would have been >> not very much harder to set both of them up to work on subtrees within the >> domain, and both would have been much more powerful and useful. I propose >> they both be fixed in future. > > https://www.chromium.org/developers/design-documents/per-page-suborigins > might be of interest. It's not exactly an easy problem to solve > though. > > > -- > https://annevankesteren.nl/ >
signature.asc
(application/pgp-signature, 495 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQEcBAEBAgAGBQJVBzF2AAoJEDRNlmYRd57ndYcH/iX9qmKzCgMi/1MHbSVWAkv8 IK7Y7WTmmZf8HgIar698HJXViB/WPsM8dAyVjQTBlj0FxosOE9xjKuEa0VM5Z2oK lF6vkl28/NIDHcmvozezg2+FiGI7eBorMlUHTNrx7tTZVGzVNgTPTGBDtlRn00wW z90NgdxmoTB5UTstLW6bbY7Os2b2l1DlcD2SdbLSYuexvXTveEteWlZ4+e+PoUZM UOA0dqc4wH4EIEkVNFxPs5SQ3jshq8zL202EYJlFox1/QNEOqgd9CO/1lZFh9zlq dP0NwHznFg4PR2kR5lGRexklsFf90b7DA5TgyAdZ8JZnebsy+D3s5LRUQxPEIBI= =GDAQ -----END PGP SIGNATURE-----