Skip to content

Port Security & Privacy considerations from docs/#181

Open
johannhof wants to merge 1 commit into
webmachinelearning:mainfrom
johannhof:spec-security-privacy-considerations
Open

Port Security & Privacy considerations from docs/#181
johannhof wants to merge 1 commit into
webmachinelearning:mainfrom
johannhof:spec-security-privacy-considerations

Conversation

@johannhof
Copy link
Copy Markdown
Contributor

@johannhof johannhof commented May 22, 2026

This is a relatively straightforward and direct port of the existing privacy and security considerations doc (docs/security-privacy-considerations.md) to the spec, in the hopes of making it easy to review and avoid repeating lengthy discussions on this text.

I have removed various sections that feel out of place in a spec, such as "Next Steps" and "Open Questions" (both were not very substantive so I think it's fine to leave them removed).

I've also made minor modifications based on a quick review of the content to make sure it makes sense in the context of the spec.

Finally, I've added a section for cross-origin boundaries considerations that we should use to describe risks in exposing tools across different origins and how developers can utilize features such as the permissions policy to keep their users safe.


Preview | Diff

@johannhof
Copy link
Copy Markdown
Contributor Author

@victorhuangwq heads up - I discussed with @domfarolino that it would make sense to move this over, given that we've received feedback in various places that it isn't straightforward to find the S&P considerations.

Copy link
Copy Markdown
Contributor

@victorhuangwq victorhuangwq left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for starting the port!

Comment thread index.bs Outdated
Comment thread index.bs
Comment thread index.bs Outdated
@victorhuangwq
Copy link
Copy Markdown
Contributor

I think just moving over the port for now and then land other major changes in separate PRs make sense. Thanks!

This is a relatively straightforward and direct port of the existing
privacy and security considerations doc (docs/security-privacy-considerations.md)
to the spec, in the hopes of making it easy to review and avoid
repeating lengthy discussions on this text.

I have removed various sections that feel out of place in a spec, such
as "Next Steps" and "Open Questions" (both were not very substantive so
I think it's fine to leave them removed).

I've also made minor modifications based on a quick review of the
content to make sure it makes sense in the context of the spec.

Finally, I've added a section for cross-origin boundaries considerations
that we should use to describe risks in exposing tools across different
origins and how developers can utilize features such as the permissions
policy to keep their users safe.
@johannhof johannhof force-pushed the spec-security-privacy-considerations branch from cb27898 to aa654b6 Compare May 22, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants