w3ctag / design-reviews

W3C specs and API reviews
Creative Commons Zero v1.0 Universal
332 stars 56 forks source link

FYI Private State Token API Permissions Policy Default Allowlist Wildcard #990

Closed arichiv closed 3 weeks ago

arichiv commented 2 months ago

こんにちは TAG-さん!

I'm requesting a TAG review of Private State Token API Permissions Policy Default Allowlist Wildcard.

Access to the Private State Token API is gated by Permissions Policy features. We proposed to update the default allowlist for both private-state-token-issuance and private-state-token-redemption features from self to * (wildcard).

Further details:

Past Evaluation: https://github.com/w3ctag/design-reviews/issues/414

jyasskin commented 2 months ago

I left some questions in https://groups.google.com/a/chromium.org/g/blink-dev/c/5jI8kLLdIFw/m/_810WhKGAwAJ, and we should wait for a reply before discussing in the TAG.

martinthomson commented 3 weeks ago

We discussed this in a breakout and have a couple concerns: