Re: [ServiceWorker] "no-cors" CSS SOP violation (#719)

> Creating new flavors of FontFace seems like overdesign to me. If style rules can't be exposed in the OM, I don't think FontFace objects should be exposed in the FontFaceSet. The ready() promise should include fonts from the inaccessible stylesheet.

I explained in the email why that's complicated and probably unworkable.  Please comment on www-style for further discussing of FontFace/etc.

> Allowing local fonts to be enumerated exposes users to fingerprinting attacks.

I didn't mention enumerating local fonts; my suggestion was for the *exact opposite*, actually.

And you can already enumerate local fonts fairly trivially through layout channels.

---
Reply to this email directly or view it on GitHub:
https://github.com/slightlyoff/ServiceWorker/issues/719#issuecomment-121367442

Received on Tuesday, 14 July 2015 20:11:16 UTC