w3c / FileAPI

File API
https://w3c.github.io/FileAPI/
Other
104 stars 44 forks source link

Export "Blob URL Store" definition #77

Closed TimothyGu closed 7 years ago

TimothyGu commented 7 years ago

This term is used in the URL Standard.

TimothyGu commented 7 years ago

Marked as non-substantive for IPR from ash-nazg.

TimothyGu commented 7 years ago

I marked this as non-substantive, but apologies if this process is usually done by a WG member rather than the PR author like myself.

annevk commented 7 years ago

Wow, seems like a major security hole in the tooling. (Reported in W3C IRC #sysreq.) Can you also generate the HTML output? Then I can commit it.

TimothyGu commented 7 years ago

@annevk Done.

annevk commented 7 years ago

Thanks for doing this by the way. This should be indexed within 24h.

tripu commented 7 years ago

@annevk, anyone can refresh validation and mark as non-substantive any PR that is not accepted yet. eg, the “ipr details” that are visible on WICG/animation-worklet#44 and WICG/budget-api#12 take you to the corresponding repo-manager page, where any user user can perform those actions. Chairs can still decide whether that makes sense or not, request further IPR commitments, etc.

annevk commented 7 years ago

That seems like a very strange model.

tripu commented 7 years ago

@annevk: I imagine @darobin adopted the simple/optimistic approach to security, and erred on the side of letting users do sensible things by default, instead of restricting actions too much.

annevk commented 7 years ago

There's no security with this model though. You might as well not have the check, since everything depends on the chairs.