Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cleanup of Security Considerations #287

Merged
merged 3 commits into from
Mar 21, 2022
Merged

Cleanup of Security Considerations #287

merged 3 commits into from
Mar 21, 2022

Conversation

mmccool
Copy link
Contributor

@mmccool mmccool commented Mar 11, 2022

Resolves Issue #254


Preview | Diff

@mmccool mmccool requested review from Citrullin and j1y3p4rk March 11, 2022 17:15
@mmccool
Copy link
Contributor Author

mmccool commented Mar 11, 2022

Let me know if I missed anything in the linked issue #254 before we merge this, as it will close that issue. There is another pending PR #286 that overlaps with this one slightly and adds another security consideration.. it should not cause actual conflicts, but some cleanup may be needed to merge both.

Have not dealt with certain other issues, like SSE Authentication. Others not explicitly linked will remain open.

@Citrullin
Copy link
Member

@mmccool This issue isn't limited to HTTP. CoAP has a similar issue. Californium enables you to access CoAP directly in the browser. This may become a feature in future browser versions.

@mmccool
Copy link
Contributor Author

mmccool commented Mar 21, 2022

@Citrullin not sure what you mean by "this issue". Can you be specific? Unfortunately the linked issue has a bunch of things in it. I am trying to clear the deck, then we can make new, smaller issues for more specific things. If you'd like to make some changes to the current PR e.g. for CoAP please do a review and suggest changes...

@mmccool
Copy link
Contributor Author

mmccool commented Mar 21, 2022

Suggest we merge this one ASAP (suggested changes can be done with issues), since we have discussed all the points addressed here at length, but hold on #286 until the other members of the Security TF have reviewed it.

@mmccool mmccool merged commit 7760a85 into w3c:main Mar 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants