CH Scratchpad: Difference between revisions
Jump to navigation
Jump to search
Line 24: | Line 24: | ||
* tweak pref RDF stuff for multiple apps & MIME: {{bug|384374}} | * tweak pref RDF stuff for multiple apps & MIME: {{bug|384374}} | ||
* proto dialog: lightweight XUL dialog (implement and hook up) {{bug|385065}} | * proto dialog: lightweight XUL dialog (implement and hook up) {{bug|385065}} | ||
* get MIME-handling working with existing ucth dialog | * get MIME-handling working with existing ucth dialog {{bug|385101}} | ||
* security review | * security review | ||
* prefs UI for changing | * prefs UI for changing {{bug|385104}} | ||
* register{content,Protocol}Handler dialogs | * register{content,Protocol}Handler dialogs {{bug|385106}} | ||
* platform specific | * platform specific app detection (win, mac, unix) {{bug|385114}} |
Revision as of 23:57, 19 June 2007
design issues
- need to handle offline case gracefully
- fragment identifiers can be used, but hacky; ping WhatWG
- static add vs. dynamic add vs. preview actions
- spec issue: GET not very RESTful for first two cases
- security issues
- spec: "should NEVER send https URIs to third-party sites"; need to design fallback behavior or change. todo: ask hixie what this protects
- how do we handle URI leakage as per HTML5 4.10.2.1. todo: does fx2 handle this? sounds hard (impossible?) to fix
- credential leakage spec verbiage sounds unimplementable
- set up security audit
- protocol handlers
- figure out what URI schemes are acceptable for both source and target
- protocol handlers
- POST issues
- use cases
- security stuff (see biesi/hixie thread in WhatWG archives)
- require https to prevent WiFi hotspot MiTM attacks?
web handlers todos
- refactor pref RDF stuff for protocol support: bug 384374 (waiting for review)
- tweak pref RDF stuff for multiple apps & MIME: bug 384374
- proto dialog: lightweight XUL dialog (implement and hook up) bug 385065
- get MIME-handling working with existing ucth dialog bug 385101
- security review
- prefs UI for changing bug 385104
- register{content,Protocol}Handler dialogs bug 385106
- platform specific app detection (win, mac, unix) bug 385114