Contact emailsjkar...@google.com

Explainer
https://github.com/explainers-by-googlers/selective-permissions-intervention

SpecificationNone

Summary

A web platform intervention designed to better align API permissions with
user intent by preventing ad scripts from accessing certain
privacy-sensitive APIs.


Blink componentBlink>PermissionsAPI
<https://issues.chromium.org/issues?q=customfield1222907:%22Blink%3EPermissionsAPI%22>

Motivation

When a user grants a website permission to access a powerful API like their
precise geolocation, microphone, camera, screen, or clipboard contents,
their consent is intended for the site, not necessarily to every
third-party script running on the page. In particular, embedded ad scripts
can currently leverage the page's permission to opportunistically access
this sensitive data. The user may not be aware that an advertisement is
accessing their information. This intervention aims to better align a
granted permission with user intent by preventing ad script in a context
with API permission from using it, reinforcing user trust and control over
their data.


Initial public proposal
https://github.com/explainers-by-googlers/selective-permissions-intervention

TAG reviewNone

TAG review statusPending

Risks


Interoperability and Compatibility

None


*Gecko*: No signal

*WebKit*: No signal

*Web developers*: No signals

*Other signals*:

WebView application risks

Does this intent deprecate or change behavior of existing APIs, such that
it has potentially high risk for Android WebView-based applications?

None


Debuggability

None


Is this feature fully tested by web-platform-tests
<https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md>
?No

Flag name on about://flagsNone

Finch feature nameNone

Non-finch justificationNone

Requires code in //chrome?False

Estimated milestones

No milestones specified


Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/4811835974615040?gate=5415705121652736

This intent message was generated by Chrome Platform Status
<https://chromestatus.com/>.

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to blink-dev+unsubscr...@chromium.org.
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAANMuaPvKk3qSGk%2BH1ExKZEB4nSfg69x_yLDaT_73GOqUa4NWQ%40mail.gmail.com.

Reply via email to