w3c / sensors

Generic Sensor API
https://www.w3.org/TR/generic-sensor/
Other
127 stars 59 forks source link

Should we check for "same origin" or "same origin-domain"? #457

Open rakuco opened 1 year ago

rakuco commented 1 year ago

The current version of the spec mentions "same origin-domain" in the context of security measures and focus requirements.

We're one of the few specs that use "same origin-domain" instead of a plain "secure origin" check/requirement, and digging through old commits and pull requests it is not clear why this choice was made.

rakuco commented 1 year ago

(also relevant: w3c/compute-pressure#187)