Permissioning, Re: Clarity over direction of work on runtime and security model?

On Wednesday, September 18, 2013 at 10:27 AM, Nilsson, Claes1 wrote:

> Generally we are now in situation where it is very unclear on what should be normatively specified and what should stay implementation specific. I think that we should agree on some plan for web system apps runtime and security that includes:
> 
> 3. What it is expected that each API specification should define relating to runtime and security.

I don't know what is "expected" and by whom, but I'm strongly of the opinion that security needs to be handled at the API level (and is mostly orthogonal to the runtime). For hosted apps, defining permissions at the manifest level seems pointless: it only helps app store reviewers, in which case this should be done inside app stores during application submission. 

Permissioning is a problem we need to solve platform wide. We need to work with other W3C WGs to solve that. 

Kind regards,
Marcos 


-- 
Marcos Caceres

Received on Thursday, 26 September 2013 20:41:31 UTC