patcg-individual-drafts / private-aggregation-api

Explainer for proposed web platform API
https://patcg-individual-drafts.github.io/private-aggregation-api/
43 stars 19 forks source link

Update explainers for fenced frame privateAggregationConfig restrictions. #154

Closed blu25 closed 2 weeks ago

blu25 commented 1 month ago

We plan to not allow setting the contextId and filteringIdMaxBytes from within a fenced frame when calling Shared Storage operations as that can be used to exfiltrate information.

Spec PR: https://github.com/patcg-individual-drafts/private-aggregation-api/pull/151