-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Description
Currently, the SEP sets the minimum required permissions for the app runtime (allow-scripts allow-same-origin). However, it doesn't address -
- Additional capabilities like camera and microphone (@yannj-fr and others)
- Hardening like
base-uri(which can affect capabilities like translations between web apps and raw HTML) or nested iframes (which might also requireui: csp: frameDomains).
These can fundamentally alter the content the server chooses to advertise or return.
We need to define the negotiation for these capabilities.
Metadata
Metadata
Assignees
Labels
No labels