Re: Runtime and Security Model for Web Applications

On 29/12/12 17:26, John Lyle wrote:
> Dear all,
> 
> I have submitted a 'Security Requirements for System Applications'
> document as a base for the execution and security model deliverables.
> 
> http://sysapps.github.com/sysapps/proposals/SecurityModel/RequirementsForSecurityModel.html

Hi John,

After a quick read of this document, I think what you guys are calling a
"System Application" would be similar to what we call a signed packaged
application.
It's not exactly the same thing but the requirements wouldn't match a
hosted application ("System applications must be installed before they
can be executed." and "A system application shall consist of a
downloadable archive [...]") and you request the package to contain a
signature and you apply the CSP policies we apply for privileged
applications.

Cheers,
--
Mounir

Received on Monday, 7 January 2013 19:43:45 UTC