Re: [w3c/manifest] Recommend user agents let users inspect and modify shortcut URLs (PR #1221)

@Copilot commented on this pull request.

## Pull request overview

Adds a privacy-focused normative recommendation to mitigate persistent user identifiers encoded in shortcut URLs, aligning shortcuts guidance with existing start URL tracking mitigations in the Manifest spec.

**Changes:**
- Expand the shortcut URL fingerprinting/privacy note to mention persistence across “clear site data”.
- Add a RECOMMENDED UA behavior: let users inspect/modify shortcut URLs on install or later.







---

💡 <a href="/w3c/manifest/new/main?filename=.github/instructions/*.instructions.md" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Add Copilot custom instructions</a> for smarter, more guided reviews. <a href="https://docs.github.com/en/copilot/customizing-copilot/adding-repository-custom-instructions-for-github-copilot" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Learn how to get started</a>.

> +        As with the [=start URL=], it is RECOMMENDED that a user agent allows
+        the user to inspect and, if necessary, modify the [=shortcut item/url=]
+        of a shortcut, upon installation or any time thereafter.

For consistency with the existing start URL tracking-mitigation note (around the earlier "Given the above..." recommendation), consider matching the phrasing/punctuation "upon installation, or any time thereafter" here as well.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/pull/1221#pullrequestreview-4768641230
You are receiving this because you are subscribed to this thread.

Message ID: <w3c/manifest/pull/1221/review/4768641230@github.com>

Received on Thursday, 23 July 2026 22:20:58 UTC