-
Notifications
You must be signed in to change notification settings - Fork 39
Open
Description
Currently, the SEP sets the minimum required permissions for the app runtime (allow-scripts allow-same-origin). However, it doesn't address -
- Additional capabilities like camera and microphone (@yannj-fr and others)
- Hardening like
base-uri(which can affect capabilities like translations between web apps and raw HTML) or nested iframes (which might also requireui: csp: frameDomains).
These can fundamentally alter the content the server chooses to advertise or return.
We need to define the negotiation for these capabilities.
chelojimenez and aharvard
Metadata
Metadata
Assignees
Labels
No labels