Re: [w3c/webpayments-payment-apps-api] Payment apps and methods, are they the same? (#35)

If you can run script on the origin you already have control of the origin. The security boundary is the origin - weren't you quoting that at me a day or two ago? That's where all the storage etc is scoped to.

Service worker made a concession for naive static hosts. It's shipped like this for a couple of years now in multiple browsers. If this is something you want to dig up & go round and round on, this isn't the thread or repo.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/webpayments-payment-apps-api/issues/35#issuecomment-247073657

Received on Wednesday, 14 September 2016 16:34:40 UTC