immersive-web / immersive-web/model-element

Require HTTPS?

Open
#109 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
HTML
Stars
86
Forks
12
Avg merge
7h 12m
Merged PRs (30d)
1

Description

One of the goals of Model is to not require any sensitive data from the user/UA to display the content. On the other hand, it seems like there is a general enthusiasm for encouraging new features to require HTTPS. It's also the case that model content (be it USDZ, glTF or any other rich definition) is also a more complicated resource to parse and pull apart, so it might be understood to need HTTPS for that reason too.

Where do folks in the CG stand on this? It's likely that WHATWG will have a significant hand in deciding the right choice, but it's good for us to present an opinion.
/facetoface

https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts

https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts/features_restricted_to_secure_contexts

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the issue discussion and the two linked MDN secure-context documents. Review how the model element is currently specified in this repository, then determine whether the project has recorded a position on HTTPS requirements. Done would require a clear decision or documented recommendation, rather than a narrowly scoped code change.

Written by the indexing model from the issue text.

Assessment

Tech stack
html
Domain
security, web-dev
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.