CfC: Transition "Secure Contexts" to CR; deadline August 2nd.

Mike West <[email protected]> Tue, 19 Jul 2016 15:21:55 +0200
Newsgroups gmane.org.w3c.tag
Message-ID <CAKXHy=dajOi5rd8gTv4z5uQiVavDMr4X3j=yz2bMLAhbGkxs=Q@mail.gmail.com>
--001a1140830630d8de0537fcf9a1
Content-Type: text/plain; charset=UTF-8

Hello, WebAppSec and TAG,

This is a call for consensus to transition Secure Contexts to Candidate
Recommendation with the document at:

https://w3c.github.io/webappsec-secure-contexts/CR.html

Since the last time we formally discussed this spec, we've cleaned up
examples and algorithms based on some very helpful feedback from folks at
Mozilla working on their implementation (thanks Boris and Jonathan!), as
well as interested folks from the TAG and elsewhere (thanks to Anne and
Domenic in particular).

The core of the specification is already used in a number of specifications
to gate certain features (like Service Workers) to contexts which offer
guarantees about their usage, and browser vendors seem interested in
implementing.

One substantive change since the last time around is the sandbox behavior
in
https://w3c.github.io/webappsec-secure-contexts/CR.html#monkey-patching-sandbox-flags,
which now defaults to forcing a sandboxed frame into "non-secure context"
status, and requires a new 'allow-secure-context' token to allow the
context to be treated as secure. It's not clear whether we can ship that
change; it's marked as "at risk" pending gathering some metrics.

Note also that this document references WHATWG documents in a few places
where the W3C version is out of date. I'm sure we'll have some exciting
conversations about those references:
https://w3c.github.io/webappsec-secure-contexts/CR.html#index-defined-elsewhere
contains a complete list.

The deadline for this CfC is in two weeks, on August 2nd. Feedback, both
positive and negative is welcome, either directly to the list, or via some
sort of clever emoji response to
https://github.com/w3c/webappsec-secure-contexts/issues/39.

Thanks!

-mike

--001a1140830630d8de0537fcf9a1
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello, WebAppSec and TAG,<div><br></div><div><div>This is =
a call for consensus to transition Secure Contexts to Candidate Recommendat=
ion with the document at:<br></div><div><br></div><div><a href=3D"https://w=
3c.github.io/webappsec-secure-contexts/CR.html">https://w3c.github.io/webap=
psec-secure-contexts/CR.html</a><br></div><div><br></div><div>Since the las=
t time we formally discussed this spec, we&#39;ve cleaned up examples and a=
lgorithms based on some very helpful feedback from folks at Mozilla working=
 on their implementation (thanks Boris and Jonathan!), as well as intereste=
d folks from the TAG and elsewhere (thanks to Anne and Domenic in particula=
r).<br></div><div><br></div><div><span style=3D"font-size:12.8px">The core =
of the specification is already used in a number of specifications to gate =
certain features (like Service Workers) to contexts which offer guarantees =
about their usage, and browser vendors seem interested in implementing.</sp=
an></div><div><span style=3D"font-size:12.8px"><br></span></div><div><span =
style=3D"font-size:12.8px">One substantive change since the last time aroun=
d is the sandbox behavior in=C2=A0<a href=3D"https://w3c.github.io/webappse=
c-secure-contexts/CR.html#monkey-patching-sandbox-flags">https://w3c.github=
.io/webappsec-secure-contexts/CR.html#monkey-patching-sandbox-flags</a>, wh=
ich now defaults to forcing a sandboxed frame into &quot;non-secure context=
&quot; status, and requires a new &#39;allow-secure-context&#39; token to a=
llow the context to be treated as secure. It&#39;s not clear whether we can=
 ship that change; it&#39;s marked as &quot;at risk&quot; pending gathering=
 some metrics.</span></div><div><br></div><div>Note also that this document=
 references WHATWG documents in a few places where the W3C version is out o=
f date. I&#39;m sure we&#39;ll have some exciting conversations about those=
 references:=C2=A0<a href=3D"https://w3c.github.io/webappsec-secure-context=
s/CR.html#index-defined-elsewhere">https://w3c.github.io/webappsec-secure-c=
ontexts/CR.html#index-defined-elsewhere</a> contains a complete list.</div>=
<div><br></div><div>The deadline for this CfC is in two weeks, on August 2n=
d. Feedback, both positive and negative is welcome, either directly to the =
list, or via some sort of clever emoji response to=C2=A0<a href=3D"https://=
github.com/w3c/webappsec-secure-contexts/issues/39">https://github.com/w3c/=
webappsec-secure-contexts/issues/39</a>.</div><div><br></div><div>Thanks!</=
div><div><br clear=3D"all"><div><div class=3D"gmail_signature">-mike</div><=
/div>
</div></div></div>

--001a1140830630d8de0537fcf9a1--