Skip to content
This repository has been archived by the owner on Nov 22, 2024. It is now read-only.

Find a way to make top-level storage access work #2

Open
johannhof opened this issue Apr 25, 2024 · 0 comments
Open

Find a way to make top-level storage access work #2

johannhof opened this issue Apr 25, 2024 · 0 comments

Comments

@johannhof
Copy link
Member

As @bvandersloot-mozilla rightfully pointed out in today's Privacy CG call, concepts like rSAFor and the Storage Access Headers wouldn't be compatible with this proposal's idea of scoping access using the identity-credentials-get policy.

I suspect the only way we can make this work would be if the RP sets a header-based permissions policy and thus opts all resources of the IdP into receiving storage access. Based on my understanding this mostly works because the only feedback about top-level Fetch use cases for Storage Access Headers comes from developers that control both the RP and IdP in some way.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant