Skip to content

Consider making permission defaults * instead of self#306

Merged
aykutbulut merged 1 commit intoWICG:mainfrom
arichiv:patch-1
Nov 8, 2024
Merged

Consider making permission defaults * instead of self#306
aykutbulut merged 1 commit intoWICG:mainfrom
arichiv:patch-1

Conversation

@arichiv
Copy link
Contributor

@arichiv arichiv commented Sep 9, 2024

Not asking for review of this yet, but posting here for consideration as part of #106


Preview | Diff

Not asking for review of this yet, but posting here for consideration as part of WICG#106
@anderagakura
Copy link

Trying to understand the blink discussion, the Issue 990 design revue in w3ctag and the privacy side :

  • In case of the user denies giving consent to X vendors / tech via the CMP (Consent Management Platform), will the token be shared cross site if a wildcard is set anyway? The question also works with the Global privacy control
  • Is there a way to prevent any adtech to redeem the token to display an ads anywhere outside? (But I think this question is already in the blink discussion)
  • Not related but somehow related, if the token is considered First party tracking (Potential risk noted in the spec) then combined with the wildcard, you have a cross site tracking : How to prevent that?

@arichiv
Copy link
Contributor Author

arichiv commented Oct 31, 2024

I replied in the blink-dev thread: https://groups.google.com/a/chromium.org/g/blink-dev/c/5jI8kLLdIFw/

@aykutbulut aykutbulut merged commit 8d6ca18 into WICG:main Nov 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants