[w3ctag/design-reviews] `sec-metadata` (#280)

Good morning, friendly TAG!

I'm requesting a (p)review of:

  - Name: `sec-metadata`
  - Specification URL: None yet.
  - Explainer, Requirements Doc, or Example code: https://github.com/mikewest/sec-metadata
  - Tests: None yet.
  - Primary contacts: @mikewest, @arturjanc

Further details (optional):

  - Relevant time constraints or deadlines: None. Just an early directional review (and invitation to a naming/spelling bikeshed).
  - [X] I am passingly familiar with the [Self-Review Questionnare on Security and Privacy](https://www.w3.org/TR/security-privacy-questionnaire/). This proposal does have some privacy implications insofar as it reveals whether a request was made from a cross-origin/site page, even in the face of a referrer policy that would prevent leaking the URL. The granularity is low enough that I'll boldly claim that the value seems to outweigh the marginal risk.
  - [X] I have reviewed the TAG's [API Design Principles](https://w3ctag.github.io/design-principles/)

You should also know that you're probably my favorite web architecture review body. Top 10, certainly.

We'd prefer the TAG provide feedback as (please select one):

  - [ ] open issues in our Github repo for each point of feedback
  - [ ] open a single issue in our Github repo for the entire review
  - [X] leave review feedback as a comment in this issue and @-notify [github usernames]

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/280

Received on Tuesday, 15 May 2018 07:07:46 UTC