CfC: Transition "Secure Contexts" to CR; deadline August 2nd.
Mike West <[email protected]> Tue, 19 Jul 2016 15:21:55 +0200
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CAKXHy=dajOi5rd8gTv4z5uQiVavDMr4X3j=yz2bMLAhbGkxs=Q@mail.gmail.com> |
--001a1140830630d8de0537fcf9a1 Content-Type: text/plain; charset=UTF-8 Hello, WebAppSec and TAG, This is a call for consensus to transition Secure Contexts to Candidate Recommendation with the document at: https://w3c.github.io/webappsec-secure-contexts/CR.html Since the last time we formally discussed this spec, we've cleaned up examples and algorithms based on some very helpful feedback from folks at Mozilla working on their implementation (thanks Boris and Jonathan!), as well as interested folks from the TAG and elsewhere (thanks to Anne and Domenic in particular). The core of the specification is already used in a number of specifications to gate certain features (like Service Workers) to contexts which offer guarantees about their usage, and browser vendors seem interested in implementing. One substantive change since the last time around is the sandbox behavior in https://w3c.github.io/webappsec-secure-contexts/CR.html#monkey-patching-sandbox-flags, which now defaults to forcing a sandboxed frame into "non-secure context" status, and requires a new 'allow-secure-context' token to allow the context to be treated as secure. It's not clear whether we can ship that change; it's marked as "at risk" pending gathering some metrics. Note also that this document references WHATWG documents in a few places where the W3C version is out of date. I'm sure we'll have some exciting conversations about those references: https://w3c.github.io/webappsec-secure-contexts/CR.html#index-defined-elsewhere contains a complete list. The deadline for this CfC is in two weeks, on August 2nd. Feedback, both positive and negative is welcome, either directly to the list, or via some sort of clever emoji response to https://github.com/w3c/webappsec-secure-contexts/issues/39. Thanks! -mike --001a1140830630d8de0537fcf9a1 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hello, WebAppSec and TAG,<div><br></div><div><div>This is = a call for consensus to transition Secure Contexts to Candidate Recommendat= ion with the document at:<br></div><div><br></div><div><a href=3D"https://w= 3c.github.io/webappsec-secure-contexts/CR.html">https://w3c.github.io/webap= psec-secure-contexts/CR.html</a><br></div><div><br></div><div>Since the las= t time we formally discussed this spec, we've cleaned up examples and a= lgorithms based on some very helpful feedback from folks at Mozilla working= on their implementation (thanks Boris and Jonathan!), as well as intereste= d folks from the TAG and elsewhere (thanks to Anne and Domenic in particula= r).<br></div><div><br></div><div><span style=3D"font-size:12.8px">The core = of the specification is already used in a number of specifications to gate = certain features (like Service Workers) to contexts which offer guarantees = about their usage, and browser vendors seem interested in implementing.</sp= an></div><div><span style=3D"font-size:12.8px"><br></span></div><div><span = style=3D"font-size:12.8px">One substantive change since the last time aroun= d is the sandbox behavior in=C2=A0<a href=3D"https://w3c.github.io/webappse= c-secure-contexts/CR.html#monkey-patching-sandbox-flags">https://w3c.github= .io/webappsec-secure-contexts/CR.html#monkey-patching-sandbox-flags</a>, wh= ich now defaults to forcing a sandboxed frame into "non-secure context= " status, and requires a new 'allow-secure-context' token to a= llow the context to be treated as secure. It's not clear whether we can= ship that change; it's marked as "at risk" pending gathering= some metrics.</span></div><div><br></div><div>Note also that this document= references WHATWG documents in a few places where the W3C version is out o= f date. I'm sure we'll have some exciting conversations about those= references:=C2=A0<a href=3D"https://w3c.github.io/webappsec-secure-context= s/CR.html#index-defined-elsewhere">https://w3c.github.io/webappsec-secure-c= ontexts/CR.html#index-defined-elsewhere</a> contains a complete list.</div>= <div><br></div><div>The deadline for this CfC is in two weeks, on August 2n= d. Feedback, both positive and negative is welcome, either directly to the = list, or via some sort of clever emoji response to=C2=A0<a href=3D"https://= github.com/w3c/webappsec-secure-contexts/issues/39">https://github.com/w3c/= webappsec-secure-contexts/issues/39</a>.</div><div><br></div><div>Thanks!</= div><div><br clear=3D"all"><div><div class=3D"gmail_signature">-mike</div><= /div> </div></div></div> --001a1140830630d8de0537fcf9a1--