w3c / dpub-pwp-ucr

Use Cases and Requirements for (Packaged) Web Publications
https://w3c.github.io/dpub-pwp-ucr/
Other
11 stars 19 forks source link

Joe and the teacher #136

Closed marcoscaceres closed 7 years ago

marcoscaceres commented 7 years ago

In section, 10.1 Limiting a PWP’s features

Joe, a student, has completed his classroom assignment which was to use PWP annotations to complete the text’s quizzes, and uploads the document to the school’s classroom management web service. The teacher can safely read the PWP on the web because the service has automatically stripped the document of all untrusted scripts.

I'm confused, how was Joe able to insert untrusted scripts in the first place? Also, if the service has stripped out scripts, then how is this a requirement on a PWP?

GarthConboy commented 7 years ago

+1

lrosenthol commented 7 years ago

I updated the text in the latest draft with him putting those scripts in the annots he added.