[mediacapture-image] Using getPhotoSettings and takePhoto allows for cross site communication (#285)

pes10k has just created a new issue for https://github.com/w3c/mediacapture-image:

== Using getPhotoSettings and takePhoto allows for cross site communication ==
It seems like you could communicate cross frames easily using takePhoto to set `PhotoSettings` in one frame, and then reading those settings back in another frame with `getPhotoSettings`. This weakens the privacy goals generally being pursed through site isolation, and would allow for cross site tracking.



Please view or discuss this issue at https://github.com/w3c/mediacapture-image/issues/285 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 16 July 2021 19:55:50 UTC