- From: Johann Hofmann <notifications@github.com>
- Date: Mon, 20 Mar 2023 12:04:46 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Monday, 20 March 2023 19:04:59 UTC
> Not sure if it's worth having the full discussion here but CORS protects against cross-site leaks. CSRF could also be done through top-level navigation? Anything else you're concerned about? Would be nice to capture it in the repo. Just to follow up here, I filed https://github.com/privacycg/requestStorageAccessForOrigin/issues/29 and https://github.com/privacycg/requestStorageAccessForOrigin/issues/30 to cover your security and reputation concerns. Let me know if anything is missing there, and sorry for not capturing those earlier. -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/808#issuecomment-1476785995 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/808/1476785995@github.com>
Received on Monday, 20 March 2023 19:04:59 UTC