Re: [w3c/permissions] Should we SecureContext the API (#235)

I was trying to poke holes in @clelland's argument, by thinking of any privacy- or security-relevant abilities a page gets by just knowing its permission state. The one that comes to mind is ads learning whether they can silently check the user's location, but that's plugged by geolocation being `[SecureContext]`, so it's not support for restricting the permissions API itself.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/permissions/issues/235#issuecomment-823484340

Received on Tuesday, 20 April 2021 17:57:38 UTC