- From: Copilot <notifications@github.com>
- Date: Thu, 23 Jul 2026 15:20:54 -0700
- To: w3c/manifest <manifest@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
- Message-ID: <w3c/manifest/pull/1221/review/4768641230@github.com>
@Copilot commented on this pull request. ## Pull request overview Adds a privacy-focused normative recommendation to mitigate persistent user identifiers encoded in shortcut URLs, aligning shortcuts guidance with existing start URL tracking mitigations in the Manifest spec. **Changes:** - Expand the shortcut URL fingerprinting/privacy note to mention persistence across “clear site data”. - Add a RECOMMENDED UA behavior: let users inspect/modify shortcut URLs on install or later. --- 💡 <a href="/w3c/manifest/new/main?filename=.github/instructions/*.instructions.md" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Add Copilot custom instructions</a> for smarter, more guided reviews. <a href="https://docs.github.com/en/copilot/customizing-copilot/adding-repository-custom-instructions-for-github-copilot" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Learn how to get started</a>. > + As with the [=start URL=], it is RECOMMENDED that a user agent allows + the user to inspect and, if necessary, modify the [=shortcut item/url=] + of a shortcut, upon installation or any time thereafter. For consistency with the existing start URL tracking-mitigation note (around the earlier "Given the above..." recommendation), consider matching the phrasing/punctuation "upon installation, or any time thereafter" here as well. -- Reply to this email directly or view it on GitHub: https://github.com/w3c/manifest/pull/1221#pullrequestreview-4768641230 You are receiving this because you are subscribed to this thread. Message ID: <w3c/manifest/pull/1221/review/4768641230@github.com>
Received on Thursday, 23 July 2026 22:20:58 UTC