Re: [w3c/manifest] Security Risks in Web App Off-scope Navigation (#747)

@mgiuca wrote:
> But would it still be possible for developers to ask for * (the whole URL space) to be stay_in_app?

No, this is specifically designed to prevent that.

> But, ultimately, I think we've struck the right balance between users and developers

As both a user and developer, I respectfully disagree :) But I am just one person. I would love to see some user research on this. My impression is that decisions like this tend to be weighted towards developers, who are the people who comment on and write the specification.

> I think we'd be going backwards if we prevented developers from being able to keep users inside the app by default.

I disagree. I think this trend really breaks the natural flow of navigating the web and just enforces the siloed app model of smartphone operating systems on the whole web.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/issues/747#issuecomment-635252408

Received on Thursday, 28 May 2020 10:19:06 UTC