w3c / security-request

Horizontal review requests will be made via issues in this repo.
4 stars 4 forks source link

DeviceOrientation Event Specification 2024-01-29 > 2024-02-29 #63

Closed anssiko closed 4 months ago

anssiko commented 5 months ago

Other comments:

This spec initially reached CR in August 2016 (history) and was retired in 2017 due to the Geolocation WG closure. In 2019 DAS WG adopted this spec and during 2019-2024 made substantial interoperability, test automation, privacy and editorial improvements as outlined in the changes section.

These changes since the previous CR Snapshot from 2016 align the specification with widely available implementations, improve interoperability including testability, and add new features for enhanced privacy protections.

For security, notably changes include the added requestPermission() method, added [SecureContext] gating to all API surfaces, making of security and privacy considerations normative and added Permissions Policy integration.

The Security and Privacy Self-Review Questionnaire self-assessment expands on a few areas that may benefit from your comment and review prior to our expected publication. Feedback on other aspects is also welcome.

Thank you for your security review!

anssiko commented 4 months ago

The review period has ended, closing as completed. Any security-related feedback at any time is welcome directly in the spec repo.