this is a topic that has been touched upon in a few other places previously, but it's been strongly suggested to me that this here list would be a good place to discuss it perhaps more thoroughly.

Basically, I've been mulling over a way of doing bulk feature requests (as in the existing Permissions draft: http://dev.w3.org/2009/dap/perms/FeaturePermissions.html) but coupled with a way to provide XSS mitigation.

I've put together a very rough draft of it. It could use a decent amount of tightening up and some more regular terminology, but I think that the idea ought to be outlined well enough that it's understandable. You can read it at:


This is just a personal proposal and isn't endorsed by any group or company. Feedback much welcome!

