Re: [w3c/webpayments-payment-apps-api] Payment apps and methods, are they the same? (#35)

Yeah, as you said in another thread the only real security boundary on the web is an origin. If this was widely understood, `http://example.com/~bob/sw.js` would be able to control the whole origin, no questions asked. Unfortunately a lot of the web is built assuming `~username` is a boundary, so we added the scoping restrictions.

Some history: https://jakearchibald.com/2014/launching-sw-without-breaking-the-web/

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/webpayments-payment-apps-api/issues/35#issuecomment-247045834

Received on Wednesday, 14 September 2016 15:11:46 UTC