Open Bug 1177856 Opened 9 years ago Updated 2 years ago

Cache API should implement full secure settings trust checks

Categories

(Core :: Storage: Cache API, enhancement)

enhancement

Tracking

()

People

(Reporter: bkelly, Unassigned)

Details

In bug 1175138 we implemented a simple scheme check for "trusted" origins. This helps with the goal of deprecating http, but its easily bypassed. We should implement the full secure settings algorithm as defined here: https://w3c.github.io/webappsec/specs/powerfulfeatures/#settings-secure
Component: DOM → DOM: Core & HTML
Component: DOM: Core & HTML → Storage: Cache API
No longer blocks: 1110136
Type: defect → enhancement
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.