Re: [blink-dev] Intent to Experiment: Storage Access Headers

2024-10-07 Thread 'Sam LeDoux' via blink-dev
Thank you Domenic. To address your notes: The TAG identified a few smaller issues in their review. Can you re-file > those as issues on > https://github.com/privacycg/storage-access-headers/issues and make sure > they get a fair discussion via the PrivacyCG? Just filed those concerns as issues

Re: [blink-dev] Intent to Experiment: Storage Access Headers

2024-10-06 Thread Domenic Denicola
LGTM to experiment, with a few notes inline. On Fri, Oct 4, 2024 at 5:05 AM 'Sam LeDoux' via blink-dev < blink-dev@chromium.org> wrote: > Contact emails > > sled...@chromium.org, cfred...@chromium.org, johann...@chromium.org > > Explainer > > https://github.com/cfredric/storage-access-headers > >

Re: [blink-dev] Intent to Experiment: Storage Access Headers

2024-10-04 Thread 'Sam LeDoux' via blink-dev
Hey, happy to give some more information on the compatibility risk. As part of the Storage Access Header implementation, we found that, for security purposes, it was necessary to send the `Origin` header in certain cross-site requests that would not previously have had the header. We've seen s

Re: [blink-dev] Intent to Experiment: Storage Access Headers

2024-10-04 Thread Mike Taylor
On 10/3/24 4:05 PM, 'Sam LeDoux' via blink-dev wrote: Contact emails sled...@chromium.org, cfred...@chromium.org, johann...@chromium.org Explainer https://github.com/cfredric/storage-access-headers