- From: Peter Linss <notifications@github.com>
- Date: Wed, 15 Mar 2023 11:31:50 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Wednesday, 15 March 2023 18:32:02 UTC
I'm not sure if this is already covered, but there needs to be a limitation on how often this method can be called. Likely restricted to a single call per user activation. Otherwise, a malicious site can use the fact that existing files can't be overwritten to probe for the existence of other files that the user has not granted access to. -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/805#issuecomment-1470557810 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/805/1470557810@github.com>
Received on Wednesday, 15 March 2023 18:32:02 UTC