w3c / webappsec-mixed-content

WebAppSec Mixed Content
https://w3c.github.io/webappsec-mixed-content/
Other
12 stars 22 forks source link

Update to account for removal of HTTPS state #32

Closed annevk closed 3 years ago

annevk commented 4 years ago

HTTPS state has been removed and this document does not account for that. I'm also not entirely sure it defines the right logic for workers. In particular data: URL workers might need some more consideration.

If this specification is being maintained I can look into writing a PR, but the open PR does not seem reassuring.

cc @domenic

estark37 commented 4 years ago

@carlosjoan91 I wonder if this is something you might be able to take on (or review a PR if @annevk sends one)?

We should fix this at least in Level 2 if not in Level 1.

carlosjoan91 commented 4 years ago

Yeah, happy to review or write a PR. @annevk: Are you still planning to write the PR? Otherwise let me know and I'll write one.

annevk commented 4 years ago

If you could take it @carlosjoan91 that'd be great. Happy to review.

carlosjoan91 commented 4 years ago

Sure, I'll send a PR.