Re: [w3ctag/design-reviews] "credentialless" embedder policy. (#582)

I think it's good to explore this as it would be a safer default and the document already calls out the problematic areas:

* How to secure nested navigation?
* What about IP-based authentication and "local" networks?

My opinion depends on how those questions are addressed. 😊

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/582#issuecomment-768088711

Received on Wednesday, 27 January 2021 07:19:34 UTC