Re: [mediacapture-main] Is more needed regarding revocation?

Section 3 "Terminology" says:
>  The terms permission, retrieve the permission state, request 
permission, delete a permission storage entry and create a permission 
storage entry are defined in [permissions]. 

However, "delete a permission storage entry" is never used in the 
document. 

The Working Draft version of the Permissions API that is referenced 
also doesn't include the definitions of "delete a permission storage 
entry" or "create a permission storage entry", although they're 
present in the latest editor's draft.

The Privacy and Security Considerations section does not make 
reference to site revocation of permissions using the Permissions API.
 The Note suggests that:
> Developers of sites with persistent permissions should be careful 
that these permissions not be abused.

However, sites do not control whether permissions are persisted or not
 (which was what prompted this issue); every user of this API needs to
 take care that these permissions are never later abused on their 
site.

(Also, "permanent permissions", "persisted permissions", "stored 
permissions" and "persistent authorization" are used apparently 
interchangeably. Is that intentional?)

-- 
GitHub Notification of comment by npdoty
Please view or discuss this issue at 
https://github.com/w3c/mediacapture-main/issues/334#issuecomment-212127260
 using your GitHub account

Received on Tuesday, 19 April 2016 21:00:36 UTC