From c5e7c2590f49d41cf628556a671a52333bdadd38 Mon Sep 17 00:00:00 2001 From: Anssi Kostiainen Date: Wed, 20 Sep 2017 12:31:03 +0300 Subject: [PATCH] Fix #193: Define extension spec Security & Privacy expectations --- index.bs | 10 +++++++--- index.html | 31 +++++++++++++++++++++---------- 2 files changed, 28 insertions(+), 13 deletions(-) diff --git a/index.bs b/index.bs index 636cbc1..f3435e9 100644 --- a/index.bs +++ b/index.bs @@ -1458,11 +1458,15 @@ as appropriate. -

Security

+

Security and Privacy

-All interfaces defined by extension specifications -should only be available within a [=secure context=]. +Extension specifications are expected to: +- conform with the generic [[#mitigation-strategies|mitigation strategies]], +- consider [[#mitigation-strategies-case-by-case|mitigation strategies applied + on a case by case basis]], +- be evaluated against the Self-Review Questionnaire on Security and Privacy + [[SECURITY-PRIVACY-QUESTIONNAIRE]].

Naming

diff --git a/index.html b/index.html index 9bf9bbf..772d595 100644 --- a/index.html +++ b/index.html @@ -1185,6 +1185,7 @@ +