W3C home > Mailing lists > Public > public-appformats@w3.org > February 2008

RE: Accountability in AC4CSR

From: Close, Tyler J. <tyler.close@hp.com>
Date: Thu, 7 Feb 2008 21:43:25 +0000
To: Ian Hickson <ian@hixie.ch>
CC: Jonas Sicking <jonas@sicking.cc>, "WAF WG (public)" <public-appformats@w3.org>
Message-ID: <C7B67062D31B9E459128006BAAD0DC3D074F803177@G6W0269.americas.hpqcorp.net>


Ian Hickson wrote:
> Access-Control is designed only to protect the _user_ who,
> when visiting
> potentially hostile sites using a trusted conforming client, may be
> exposed to code that will try third-party access, [...]

The current design clearly doesn't provide any such protection since the _user_'s consent is not required for the third-party site to issue the cross-domain request. Just because a third-party site wants to delete my email and has the permission to do so with my consent, doesn't mean it should be allowed to go ahead and do so without my consent. The current design never requires the user's consent to wield the user's authority.

--Tyler
Received on Thursday, 7 February 2008 21:44:15 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Thursday, 7 February 2008 21:44:15 GMT