Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Permissions Policy reports for iframes #1050

Open
1 task done
shhnjk opened this issue Feb 11, 2025 · 0 comments
Open
1 task done

Permissions Policy reports for iframes #1050

shhnjk opened this issue Feb 11, 2025 · 0 comments

Comments

@shhnjk
Copy link

shhnjk commented Feb 11, 2025

TAGの皆様、こんにちは!

I'm requesting a TAG review of Permissions Policy reports for iframes.

I'd like to introduce a new Permissions Policy violation type called Potential Permissions Policy violation, which will only look at Permissions Policy (including report-only policy) and the allow attribute set in iframes to detect the conflict between Permissions Policy enforced vs permissions propagated to iframes. The Potential Permissions Policy violation reports will be sent to embedder's reporting endpoint, instead of iframe's reporting endpoint.

Further details:

  • I have reviewed the TAG's Web Platform Design Principles
  • Previous early design review, if any: N/A
  • Relevant time constraints or deadlines: I'd like to ship this soon
  • The group where the work on this specification is currently being done: WebAppSec
  • Major unresolved issues with or opposition to this specification:
  • This work is being funded by: Google
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant