Disabling geolocation permissions by default in cross-origin iframes
Categories
(Core :: DOM: Geolocation, enhancement)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox71 | --- | fixed |
People
(Reporter: tnguyen, Assigned: tnguyen)
References
(Blocks 1 open bug)
Details
Attachments
(1 file)
The new model relationship between Feature policy and permission depends on disabling permissions by default in cross-origin iframes. That change will require websites to explicitly allow permissions for cross-origin iframes, otherwise those iframes will have permission requests denied
I am going to fix Geolocation permission denied by default here.
| Assignee | ||
Updated•6 years ago
|
| Assignee | ||
Comment 1•6 years ago
|
||
Comment 3•6 years ago
|
||
| bugherder | ||
Updated•6 years ago
|
Comment 4•6 years ago
|
||
:tnguyen, this test is failing when fission is enabled (bug 1580074). Could you please look into this so we can enable it for Fission?
| Assignee | ||
Comment 5•6 years ago
•
|
||
I still don't know the reason why Feature Policy does not work in a new process of cross origin iframe, but I will take a look. I file a bug for that, bug 1580462
| Assignee | ||
Updated•6 years ago
|
Comment 6•6 years ago
|
||
This bug was discussed today at TPAC 2019 at the Devices & Sensors WG, tracking issue: https://github.com/w3c/geolocation-api/issues/10
Description
•