Re: Restricting API access

On Mon, 15 Jun 2009 18:47:17 +0200, Andrei Popescu <andreip@google.com> wrote:
> I think we do reference exactly that definition. Anyway, I thought the
> spec is clear in that respect but improvements are, of course, welcome
> :) Do you happen to have a suggestion?

I saw you use it in the definition of PERMISSION_DENIED though it is not referenced (e.g. by saying "The term origin is defined in HTML5. [HTML5]) and it talks about application origin which is somewhat ambiguous as you could have multiple applications on a single origin.

I think that once the text in

  http://lists.w3.org/Archives/Public/public-geolocation/2008Oct/0070.html

is integrated wording could be added there. E.g. "If a user grants an application permission this permission SHOULD be scoped to the origin of the application." and where it talks about revoking permission I would do s/application/origin/.

(Maybe also in general prefix application with "Web ".)


-- 
Anne van Kesteren
http://annevankesteren.nl/

Received on Monday, 15 June 2009 17:08:16 UTC