Re: [whatwg/webidl] Consider adding an `[InjectionMitigated]` extended attribute. (Issue #1440)

cc @domenic, @johnwilander, @camillelamy, and @lweichselbaum who participated in the conversation at TPAC for additional feedback, along with @rbyers and @bvandersloot-mozilla who seemed at least conceptually interested in this kind of thing for digital credentials (if worried about deployment cost).

I should also have mentioned that we're experimenting with this in Chromium for a [single API with some weird Origin Trial constraints](https://source.chromium.org/chromium/chromium/src/+/main:third_party/blink/renderer/modules/mediastream/media_devices.idl;drc=3f8f9df137702ca101cd084fd1ccb86628276f3e;l=36). It seems fairly straightforwardly implementable, and the constraints seem robust-enough given our current experience with both CSP and Trusted Types.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/webidl/issues/1440#issuecomment-2396431094
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/webidl/issues/1440/2396431094@github.com>

Received on Monday, 7 October 2024 09:43:23 UTC