|
View:
New views
5 Messages
—
Rating Filter:
Alert me
|
|
|
[widgets] viewmodes specHi there, At the last widgets call I agreed to ask OMTP BONDI members
if there was any feedback on viewmodes. We didn’t receive a lot of views
but one thing I raised was that as far as I can tell, there is no text to cover
off invisible widgets or widgets of, for example height and width 1x1. There
may be a valid reason for someone to have an invisible widget but there are
still some abuse scenarios – for example, if someone created a
transparent widget that then maximises in front of your payment application
just as you go to enter your PIN or password it could be a major issue. I’m not sure that anyone has started work on any widget
security guidelines? Thanks, David. David
Rogers |
|
|
|
|
|
[widgets] Security Guidelines for Widgets? [Was: Re: [widgets] viewmodes spec]On Oct 26, 2009, at 5:23 AM, ext David Rogers wrote:
> Do you know if anybody has started work on any security guidelines > for widgets? I am not aware of any such work. -Regards, Art Barstow > I noticed that in the “Web Security Context: User Interface > Guidelines”, for example this requirement[1] there may be some > conflict with widgets / potential to put requirements there for the > item below and others? > > Thanks, > > David. > > [1] http://www.w3.org/TR/wsc-ui/#keepchromevisible-goodpractice |
|
|
Re: [widgets] Security Guidelines for Widgets? [Was: Re: [widgets] viewmodes spec]On Tue, Oct 27, 2009 at 4:26 PM, Arthur Barstow <Art.Barstow@...> wrote:
> On Oct 26, 2009, at 5:23 AM, ext David Rogers wrote: > >> Do you know if anybody has started work on any security guidelines for >> widgets? > > I am not aware of any such work. > Please see: http://lists.w3.org/Archives/Public/public-webapps/2009OctDec/0364.html This is now in the spec. I've requested people contribute some text. -- Marcos Caceres http://datadriven.com.au |
|
|
Re: FW: [widgets] viewmodes spec2009/10/26 David Rogers <david.rogers@...>:
> Hi Art and Marcos, > > > > I didn’t see this point discussed in the last widgets meeting minutes. Do you know if anybody has started work on any security guidelines for widgets? I noticed that in the “Web Security Context: User Interface Guidelines”, for example this requirement[1] there may be some conflict with widgets / potential to put requirements there for the item below and others? > We have not yet started work on this. We could certainly add a security considerations section to one the view mode specs (as we have done with P&C and with Dig Sig). Please feel free to contribute some tests. -- Marcos Caceres http://datadriven.com.au |
| Free embeddable forum powered by Nabble | Forum Help |