RE: Please review: Safe Web Form Editor in Editor's Draft

I see your point. In that case we are talking about three ways of
entering text strings, and not two as this section states at the
beginning:

1. Typing in the whole text string
2. Auto-completion of previously entered text-string to the same web
site
3. Explicit user selection among history-stored text-strings (i.e.
different user action...)

We can keep the current first paragraph and, to avoid confusion, add a
sentence for the 3rd way of entering text strings.

Are there any findings somewhere that describe why auto-completion
across sites is not good?

Luis
-----Original Message-----
From: public-wsc-wg-request@w3.org [mailto:public-wsc-wg-request@w3.org]
On Behalf Of Close, Tyler J.
Sent: den 11 oktober 2007 22:18
To: public-wsc-wg@w3.org
Subject: RE: Please review: Safe Web Form Editor in Editor's Draft


Hi Luis,

No, you don't have to type in the whole text string again. You can
select it from the history menu. This feature is discussed in the
paragraph immediately after the one you quoted from.

To avoid this confusion, perhaps we could omit discussion of
auto-completion and just rely on the existing normative statement:
"Further, the user action to select a text string previously submitted
to the current site MUST be different from that to select a text string
previously submitted to some other site."

I believe this constraint already prohibits the auto-completion
interface I am worried about.

--Tyler 

> -----Original Message-----
> From: public-wsc-wg-request@w3.org
> [mailto:public-wsc-wg-request@w3.org] On Behalf Of Luis Barriga
> Sent: Thursday, October 11, 2007 7:46 AM
> To: Thomas Roessler; Close, Tyler J.
> Cc: public-wsc-wg@w3.org
> Subject: RE: Please review: Safe Web Form Editor in Editor's Draft
> 
> 
> Question on section 6.5 Selection of a text string
> 
> "... The text field MUST NOT provide auto-completion of stored editor 
> bar text strings that have not been previously submitted to the 
> currently displayed web site"
> 
> Does this mean that I have to type in my whole phone number for each 
> new trusted web site that needs it?
> 
> Luis
> 
> -----Original Message-----
> From: public-wsc-wg-request@w3.org
> [mailto:public-wsc-wg-request@w3.org]
> On Behalf Of Thomas Roessler
> Sent: den 11 oktober 2007 13:44
> To: Close, Tyler J.
> Cc: public-wsc-wg@w3.org
> Subject: Please review: Safe Web Form Editor in Editor's Draft
> 
> 
> Tyler,
> 
> the current editor's draft includes the Safe Web Form Editor:
> 
>   Web Security Context: Experience, Indicators, and Trust
>   Editor's Draft $Date: 2007/10/11 11:38:08 $
>   
>   http://www.w3.org/2006/WSC/drafts/rec/rewrite.html
>   http://www.w3.org/2006/WSC/drafts/rec/rewrite.html#ceremonies
> 
> I have made a number of changes to the text to abstract from the 
> concrete text given, and to clarify the field/attribute confusion.
> 
> Please review the material and let me know what other changes you need

> to see in the draft before we can publish.
> 
> Thanks,
> --
> Thomas Roessler, W3C  <tlr@w3.org>
> 
> 
> 

Received on Friday, 12 October 2007 11:39:03 UTC