Re: [w3c/browser-payment-api] should .show() be user gated? (#486)

This would also help to prevent:
1) annoying drive-by requests like we see with alert/confirm spamming and 
2) clickjacking attacks if a UA allows a one-click purchase (of course delays on the button are another way to mitigate the latter).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/browser-payment-api/issues/486#issuecomment-289977539

Received on Wednesday, 29 March 2017 04:17:23 UTC