Re: [manifest] Must manifests be same-origin? (#360)

I think that it might work and we definitely need to support the use-case of submitting manifest.json. It sounds like MS needs it, and we personally need it for Crosswalk :-)

What about fullscreen and phishing/MITM? I guess that anyone could create an app which starts in fullscreen and embeds another site in a full viewport iframe. Can we somehow guard us against that?

---
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/issues/360#issuecomment-94011794

Received on Friday, 17 April 2015 15:41:18 UTC