Re: [w3ctag/design-reviews] Serial API (#431)

Hi,

Security/privacy self-check comments. 
 
> If an implementation chooses to make these permissions persist across browsing sessions then the availability of a particular device consitutes a piece of state

Any observations about implementations choosing to go for persistent permissions? Why leaving it to implementations?

> A privacy-sensitive user is expected to not grant

I would be cautious with wording suggesting a particular expectations from users...


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/431#issuecomment-550019216

Received on Tuesday, 5 November 2019 21:04:50 UTC