Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mozilla feedback: Related Origins #2186

Open
wants to merge 2 commits into
base: level3
Choose a base branch
from

Conversation

timcappalli
Copy link
Member

@timcappalli timcappalli commented Oct 23, 2024

mozilla/standards-positions#1052 (comment)

Addresses Mozilla's feedback around Related Origins.

  • Requires well-known to be served via HTTPS by the RP
  • Requires https: scheme for all well-known calls by the client
  • Requires https: for all redirects
  • Requires calls by client to well-known endpoint to not be credentialed and not include referrer

/ghcc @dveditz

The following tasks have been completed:

  • Modified Web platform tests (link)

Implementation commitment:

Documentation and checks

  • Affects privacy
  • Affects security
  • Updated explainer (link)

Preview | Diff

@timcappalli
Copy link
Member Author

Spoke to @g-davidson offline (as he is unable to approve in Github for some reason) and he is OK with these changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants