Re: [w3ctag/design-reviews] FedCM as a trust signal for the Storage Access API (Issue #992)

hadleybeeman left a comment (w3ctag/design-reviews#992)

Thanks for bringing this here. This doesn't need too much additional analysis. The explainer is pretty complete, to the point of being more justification than is really necessary. There is a simpler story to tell, which is that granting access to FedCM creates a communication channel between RP and IdP. Once that channel exists, cross-site (and cross-origin) linkability is established. There is no additional privacy benefit to be obtained from withholding cross-site cookies.

The extra thought that you have put into the permissions architecture is appreciated; the choice made to keep the permissions distinct, but use an automatic storage access grant is well motivated and seems like the right choice.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/992#issuecomment-3083411196
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/992/3083411196@github.com>

Received on Thursday, 17 July 2025 09:53:51 UTC