Re: css3-fonts: should not dictate usage policy with respect to origin

Glenn wrote:

> I believe Samsung could agree to making an authorial opt-in mechanism a 
> mandatory feature on UAs that access WOFF; however, I believe we will 
> not be able to agree with a policy that requires use of a restrictive 
> opt-out mechanism which by default would prevent access.

Would this be satisfactory, in terms of a Webfonts Conformance 
Specification (exact wording to be drafted, this is just to capture the 

 UAs MUST respect author header settings restricting
 or relaxing same origin.

 UAs SHOULD, by default, treat webfont resources as
 same origin restricted.

I think many of us would want to make that second statement a SHOULD 
rather than a MAY, simply to encourage UA makers to give serious thought 
as to whether they have a good reason not to treat webfont resources in 
this way.


