Re: [w3c/manifest] Security Risks in Web App Off-scope Navigation (#747)

Note that we are working on #748 to add non-normative note and acknowledge the reporters of this issue.

@benfrancis It sounds like your suggestion would remove the ability to display an off-scope page within the application context (except in "some edge cases"?). I agree that would solve the phishing risk, but at the cost of functionality that developers want (i.e., not kicking users out of their app). It would also break key workflows, such as authentication (maybe these are the edge cases you're talking about).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/issues/747#issuecomment-635080532

Received on Thursday, 28 May 2020 03:51:11 UTC