Re: [w3ctag/design-reviews] Signature-Based Integrity. (Issue #1041)

martinthomson left a comment (w3ctag/design-reviews#1041)

Having spent a little time discussing a few issues with Mike on his issue tracker, I'm starting to think that this probably needed to be marked as an early review rather than a final review.  There are a couple of pretty fundamental [issues](https://github.com/WICG/signature-based-sri/issues) that still need resolution.  In particular, https://github.com/WICG/signature-based-sri/issues/45, https://github.com/WICG/signature-based-sri/issues/44, https://github.com/WICG/signature-based-sri/issues/38, and (I can't find the number) a very serious question about whether the signature needs to cover the (current) request URL.

Should this spend a little more time in the shop before we review it like it's done?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/1041#issuecomment-2664580963
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/1041/2664580963@github.com>

Received on Tuesday, 18 February 2025 04:28:30 UTC