w3c / w3c/FileAPI

Self-Review Questionnaire for FileAPI: Security and Privacy

Aperta
#214 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@mkruisselbrink ci sta già lavorando.

Dal 11/11/2025.

Lingua principale
HTML
Stelle
118
Fork
52
Merge medio
9g 16h
PR unite (30g)
1

Descrizione

Self-Review Questionnaire: Security and Privacy

The full questionnaire is at https://w3c.github.io/security-questionnaire/.

For your convenience, a copy of the questionnaire's questions is included here in Markdown, so you can easily include your answers in an explainer.


  1. What information does this feature expose,
    and for what purposes?
  2. Do features in your specification expose the minimum amount of information
    necessary to implement the intended functionality?
  3. Do the features in your specification expose personal information,
    personally-identifiable information (PII), or information derived from
    either?
  4. How do the features in your specification deal with sensitive information?
  5. Does data exposed by your specification carry related but distinct
    information that may not be obvious to users?
  6. Do the features in your specification introduce state
    that persists across browsing sessions?
  7. Do the features in your specification expose information about the
    underlying platform to origins?
  8. Does this specification allow an origin to send data to the underlying
    platform?
  9. Do features in this specification enable access to device sensors?
  10. Do features in this specification enable new script execution/loading
    mechanisms?
  11. Do features in this specification allow an origin to access other devices?
  12. Do features in this specification allow an origin some measure of control over
    a user agent's native UI?
  13. What temporary identifiers do the features in this specification create or
    expose to the web?
  14. How does this specification distinguish between behavior in first-party and
    third-party contexts?
  15. How do the features in this specification work in the context of a browser’s
    Private Browsing or Incognito mode?
  16. Does this specification have both "Security Considerations" and "Privacy
    Considerations" sections?
  17. Do features in your specification enable origins to downgrade default
    security protections?
  18. What happens when a document that uses your feature is kept alive in BFCache
    (instead of getting destroyed) after navigation, and potentially gets reused
    on future navigations back to the document?
  19. What happens when a document that uses your feature gets disconnected?
  20. Does your spec define when and how new kinds of errors should be raised?
  21. Does your feature allow sites to learn about the user's use of assistive technology?
  22. What should this questionnaire have asked?

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.