Re: [w3ctag/design-reviews] "credentialless" embedder policy. (#582)

As the issue is no longer about iframe, could this be just a CSP? (I'm fine with this being COEP, but wondering where it fits better).
Also, based on the underlying issue driving this, it might be good to segment caches (SW, native) around the  "includeCredentials" value, like public and private caches, or use its value as a cache key. (See https://github.com/w3c/ServiceWorker/issues/1592, thanks @annevk for the pointer)

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/582#issuecomment-887322852

Received on Tuesday, 27 July 2021 08:35:47 UTC