Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security scopes #2

Open
sashafirsov opened this issue Dec 11, 2022 · 6 comments
Open

Security scopes #2

sashafirsov opened this issue Dec 11, 2022 · 6 comments

Comments

@sashafirsov
Copy link
Member

sashafirsov commented Dec 11, 2022

Some DCE would act as "mediator" and pipe the content transparently with a little adjustment of content. Whether it is an UX activities analytics, localization, or accessibility decorator application author needs a level of control what particular DCE instance/html include/html module has access to and able to change. The reasons would vary. From security( why accessibility layer should track user activities?) to insulation of apps from different domains( why give app keys access to foreign domain).

What would scope control?

  • own baseURI to resolve references to dependent resources
    *own importmaps to resolve non-relative and non-absolute URIs
  • own permitted domains to work against
  • request mapping and transformation pipeline
  • DOM/CSS insulation level. From none to full which matches no insulation as in usual STYLE tag to shadowDOM.
  • Scope variables, a substitution to globals.

scope presets

In addition to none and anonymous the scopes can be defined and named by context owner.

Using the scope of same name defines the concept of library - a related set of components which share same configuration and insulation layers.

scope inheritance

Since scopes are working within context, it's hierarchy is applied for scopes. But on the outer(owner) level the inner scopes can be redefined and passed through.
For example, Bootstrap CSS library can be named on page level as bootstrap-css and components which use or override its rules would have scope="bootstrap-css".

@sashafirsov
Copy link
Member Author

Is there a need for explicit scopes mix? scope="a,b"?

@sashafirsov
Copy link
Member Author

sashafirsov commented Dec 11, 2022

scope definition

Is a subset of DWA descriptor. Perhaps is identical?

@sashafirsov
Copy link
Member Author

The scope is a candidate for [Proposal] context and scope in DCE, HTML module, DWA, HTML include, template
in https://discourse.wicg.io/

@sashafirsov
Copy link
Member Author

History

Since very beginning of HTML the scopes been extensively used

Glossary

@sashafirsov
Copy link
Member Author

sashafirsov commented Dec 13, 2022

domain and subdomain scope

in similar fashion as cookies. If Domain is specified, then subdomains are always included.

@sashafirsov
Copy link
Member Author

sashafirsov commented Apr 5, 2023

the scope in DCE POC is limited to DCE root as associated data slice set. Other scopes or page level interaction is not exposed, hence no need for scope limitations.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant