Re: [ambient-light] Fix #37: Add cross-origin leaks, hijacking browsing history

Hello. Looks sound (perhaps it would benefit from some proof reading though).

@alexshalamov can you elaborate how top-level-browsing-context and losing-focus mitigate the risks discussed here? 

Note: I would still allow permissions. In the original issue I actually addressed that some mitigations (frequency/precision) reduce risk, but may not solve all "instances". In that case, we should consider at least documenting that.

-- 
GitHub Notification of comment by lknik
Please view or discuss this issue at https://github.com/w3c/ambient-light/pull/38#issuecomment-325731281 using your GitHub account

Received on Tuesday, 29 August 2017 17:10:52 UTC