Re: [w3ctag/design-reviews] Deprecating `document.domain`. (#564)

Hi all. Just a note that we're picking this up on the Chromium side.

The plan is largely as initially proposed here: Implement a document policy (or [whatever it ends up being named](https://github.com/WICG/document-policy/issues/26)) to enable/disable document.domain setting, initially being default-enabled (i.e., opt-out), and to then switch the default (to opt-in) after a bake-in period. So the capability remains but will eventually require an opt-in. This in turn would then allow us to improve origin-level isolation. Timeline is still uncertain, but we're hoping for the first step in one of the coming milestones (M96 or so), and to switch the default a few months later (provided the earlier steps go well).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/564#issuecomment-916753235

Received on Friday, 10 September 2021 09:07:53 UTC