Re: "Requirements for Powerful Features" strawman.

>> My .02 - I think this needs to be a TAG finding for visibility, but REC track has charms too; maybe a joint deliverable makes sense. Adding Dan for his thoughts.
> Given that it's something that needs to be implemented, it seems
> highly inappropriate as finding.

Yes, we came to the same conclusion. I think a finding, if we produce one, would be a high-level policy-ish document; WebAppSec would define the implementation (presumably with TAG input).

See update:


Mark Nottingham

