Skip to content

[Discuss] Limit access to the API based on known allow listed origins #59

@kdenhartog

Description

@kdenhartog

In order to reduce harmful over-requesting of 3P attested information it would be useful to have a registry of origins allowed to request credentials. If the origin is not listed then the site would not be able to prompt the user for permission of the credential.

The default lists will need to be maintained. Two proposals for this registry would be W3C or country specific privacy commissioners who publish them in a way that the browser services can load and store them.

Should we also allow users to be able to override them and if so what is the proper UX for this? If so would it make sense to do this as a part of the permissions UX currently implemented or as a UX with more friction?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions