Re: [w3ctag/design-reviews] Moving local files with the File System Access API (Issue #805)

I'm not sure if this is already covered, but there needs to be a limitation on how often this method can be called. Likely restricted to a single call per user activation. 

Otherwise, a malicious site can use the fact that existing files can't be overwritten to probe for the existence of other files that the user has not granted access to. 

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/805#issuecomment-1470557810
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/805/1470557810@github.com>

Received on Wednesday, 15 March 2023 18:32:02 UTC