W3C home > Mailing lists > Public > public-geolocation@w3.org > June 2009

Re: Restricting API access

From: Anne van Kesteren <annevk@opera.com>
Date: Mon, 15 Jun 2009 19:07:33 +0200
To: "Andrei Popescu" <andreip@google.com>
Cc: "public-geolocation@w3.org" <public-geolocation@w3.org>
Message-ID: <op.uvksivth64w2qv@annevk-t60>
On Mon, 15 Jun 2009 18:47:17 +0200, Andrei Popescu <andreip@google.com> wrote:
> I think we do reference exactly that definition. Anyway, I thought the
> spec is clear in that respect but improvements are, of course, welcome
> :) Do you happen to have a suggestion?

I saw you use it in the definition of PERMISSION_DENIED though it is not referenced (e.g. by saying "The term origin is defined in HTML5. [HTML5]) and it talks about application origin which is somewhat ambiguous as you could have multiple applications on a single origin.

I think that once the text in

  http://lists.w3.org/Archives/Public/public-geolocation/2008Oct/0070.html

is integrated wording could be added there. E.g. "If a user grants an application permission this permission SHOULD be scoped to the origin of the application." and where it talks about revoking permission I would do s/application/origin/.

(Maybe also in general prefix application with "Web ".)


-- 
Anne van Kesteren
http://annevankesteren.nl/
Received on Monday, 15 June 2009 17:08:16 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Monday, 7 December 2009 18:13:32 GMT