w3c / deviceorientation

W3C Device Orientation spec
https://www.w3.org/TR/orientation-event/
Other
49 stars 32 forks source link

Security and privacy section must be normative #46

Closed alexshalamov closed 5 years ago

alexshalamov commented 6 years ago

Security & Privacy section must be made normative to avoid interoperability issues related to cross-origin API access, exposure of powerful features only to secure context, etc.

Currently, browsers implement cross-origin access to the API differently:

Cross-origin access is blocked in:

Cross-origin access is allowed in:

Proposal:

anssiko commented 5 years ago

Fixed in https://github.com/w3c/deviceorientation/commit/4f91c34308d35d1a4da32be71a9b17b62248d1e3