w3ctag / security-questionnaire

A security/privacy review questionnaire for W3C specs
https://w3ctag.github.io/security-questionnaire/
Creative Commons Zero v1.0 Universal
25 stars 34 forks source link

This questionnaire should ask about SecureContext restrictions #173

Open domenic opened 1 month ago

domenic commented 1 month ago

It recently occurred to me that several explainers I wrote (for built-in AI features) should probably be restricted to a secure context. I just didn't realize it while writing the explainer.

A question in the questionnaire (which I did fill out) would have made me realize it sooner.

Although the full guidance on when features are restricted is probably difficult to summarize (and perhaps still controversial), I think a question like

Have you considered whether your feature would be best restricted to secure contexts?

would be helpful for others in my situation.