w3c / webappsec

Web Application Security Working Group repo
601 stars 148 forks source link

"End-to-End Encryption email" is missing an actual proposal #646

Open plehegar opened 4 months ago

plehegar commented 4 months ago

From AC Review: [[ We are concerned about the new "End-to-End Encryption email" proposed optional deliverable because it looks out of scope for the working group: https://www.w3.org/2024/01/proposed-wg-webappsec.html#scope

We also note that the link in the deliverables section to "End-to-End Encryption email" is also only to a section of minutes of a meeting from nearly 6 months ago, and NOT a Proposal draft (whether incubated or not) or even an Explainer draft, which is highly unusual and unexpected. This seems like a Charter drafting clerical error of leaving in the wrong link, since the linked minutes do say there is a "draft that we have" that "if there's enough interest we will publish", so presumably that publication may (should?) have happened in the past 6 months since one implementer proposed it and another implementer said "There is interest".

Since we are not sure if there was an attempt to expand the Scope but it wasn't written up, and/or if there was a clerical error of failing to link to an actual proposal, or if this was perhaps a Charter editing-in-progress tentative addition that was errantly not removed before taking to an AC poll, we do not feel we have enough information to propose a specific set of actions to resolve these concerns.

We are expressing our concerns (on apparent scope violation and failure to link to an actual proposal) but we are not making this a Formal Objection because optimistically the error or errors may again be clerical (rather than substantial) in nature, and we expect the Team to address such corrections before adopting an updated Web Application Security Working Group Charter. ]]

cc https://github.com/w3c/strategy/issues/426

plehegar commented 4 months ago

cc @marcoscaceres

plehegar commented 4 months ago

proposal is at https://github.com/WebKit/explainers/tree/main/remote-cryptokeys

plehegar commented 4 months ago

(second part of the proposal is expected by end of this week)

cc @hober

marcoscaceres commented 4 months ago

We can have the second part most likely by next week.

plehegar commented 3 months ago

it's been 2 weeks now and still no actual; proposal. at this point, this should be dropped.

marcoscaceres commented 3 months ago

The https://github.com/WebKit/explainers/tree/main/remote-cryptokeys is part of it. Sorry, I've been dealing with some health issues last few days which delayed things. I'll put it up in the next few hours.

marcoscaceres commented 3 months ago

Sorry for the delay on our side: https://github.com/WebKit/explainers/blob/main/cryptographic-message-syntax-API/README.md