Formalizing our permissions model - next steps

It seems that my suggestion for formalizing our permissions model
(posted Nov 16) hasn't generated any active resistance, and I've gotten
some feedback off-list that's of the form "seems good, please go on
pushing it".

After some discussion, it seems to me that the easiest way forward is to
ask the WEBAPPSEC WG to incorporate this proposal into their permissions
document. This should at least generate reviews by people who know what
their model is intended to be used for.

Once it's been incorporated there, referring to these concepts from our
various documents should be a small matter of editing.

If you have opinions on this proposed plan (positve or negative), please


Received on Friday, 4 December 2015 15:48:30 UTC