w3ctag / design-reviews

W3C specs and API reviews
Creative Commons Zero v1.0 Universal
326 stars 55 forks source link

Private Network Access (aka CORS-RFC1918) permission to relax mixed content #751

Closed iVanlIsh closed 2 years ago

iVanlIsh commented 2 years ago

Wotcher TAG!

I'm requesting a TAG review of Private Network Access permission to relax mixed content.

A new permission to relax mixed content restrictions for private network resources while secure context restriction enabled on public websites which initialed request to private network.

Further details:

You should also know that...

The major part of the spec has already been reviewed in https://github.com/w3ctag/design-reviews/issues/572 Here we forced on permission part to relax mixed content restrictions.

We'd prefer the TAG provide feedback as :

🐛 open issues in our GitHub repo for each point of feedback

ylafon commented 2 years ago

With @hadleybeeman @torgo and @maxpassion we reviewed this in our F2F. The only clarification needed is if/how the ipv6 case is handled, but otherwise it looks good to us.

To point 1 of the security & privacy self-review, any proxying from the local network is a risk that the owner accepts when setting it up, and most probably something that the prompt would be enough to alert the owner.

Thanks for flying TAG!