Skip to content

Commit f502eec

Browse files
committed
[css-contain-1][css-contain-2] Set up separate privacy and security sections
1 parent 0a422db commit f502eec

File tree

2 files changed

+20
-122
lines changed

2 files changed

+20
-122
lines changed

css-contain-1/Overview.bs

Lines changed: 10 additions & 59 deletions
Original file line numberDiff line numberDiff line change
@@ -1336,72 +1336,23 @@ Possible Paint-Containment Optimizations</h4>
13361336
3. Because they are guaranteed to be stacking contexts,
13371337
scrolling elements can be painted into a single GPU layer.
13381338

1339-
Privacy and Security Considerations {#priv-sec}
1340-
==============================================
13411339

1342-
This specification introduces no new privacy or security considerations.
1340+
<h2 id=privacy oldids="priv-sec">
1341+
Privacy Considerations</h2>
13431342

1344-
Like any other CSS specification, it affects the rendering of the document,
1345-
but does not introduce any special ability to present content in a misleading way
1346-
that was not previously available through other CSS modules
1347-
and that isn't inherent to the act of formatting the document.
1343+
There are no known privacy impacts of the features in this specification.
13481344

1349-
The <a href="http://www.w3.org/2001/tag/">TAG</a> has developed a <a href="https://www.w3.org/TR/security-privacy-questionnaire/">self-review questionnaire</a>
1350-
to help editors and Working Groups evaluate the risks introduced by their specifications.
1351-
Answers are provided below.
13521345

1353-
<dl>
1354-
<dt>Does this specification deal with personally-identifiable information?
1355-
<dd>No.
1346+
<h2 id=security>
1347+
Security Considerations</h2>
13561348

1357-
<dt>Does this specification deal with high-value data?
1358-
<dd>No.
1349+
There are no known security impacts of the features in this specification.
13591350

1360-
<dt>Does this specification introduce new state for an origin that persists across browsing sessions?
1361-
<dd>No.
1351+
Like any other CSS specification, it affects the rendering of the document,
1352+
but does not introduce any special ability to present content in a misleading way
1353+
that was not previously available through other CSS modules
1354+
and that isn't inherent to the act of formatting the document.
13621355

1363-
<dt>Does this specification expose persistent, cross-origin state to the web?
1364-
<dd>No.
1365-
1366-
<dt>Does this specification expose any other data to an origin that it doesn’t currently have access to?
1367-
<dd>No.
1368-
1369-
<dt>Does this specification enable new script execution/loading mechanisms?
1370-
<dd>No.
1371-
1372-
<dt>Does this specification allow an origin access to a user’s location?
1373-
<dd>No.
1374-
1375-
<dt>Does this specification allow an origin access to sensors on a user’s device?
1376-
<dd>No.
1377-
1378-
<dt>Does this specification allow an origin access to aspects of a user’s local computing environment?
1379-
<dd>No.
1380-
1381-
<dt>Does this specification allow an origin access to other devices?
1382-
<dd>No.
1383-
1384-
<dt>Does this specification allow an origin some measure of control over a user agent’s native UI?
1385-
<dd>No.
1386-
1387-
<dt>Does this specification expose temporary identifiers to the web?
1388-
<dd>No.
1389-
1390-
<dt>Does this specification distinguish between behavior in first-party and third-party contexts?
1391-
<dd>No.
1392-
1393-
<dt>How should this specification work in the context of a user agent’s "incognito" mode?
1394-
<dd>No difference in behavior is needed.
1395-
1396-
<dt>Does this specification persist data to a user’s local device?
1397-
<dd>No.
1398-
1399-
<dt>Does this specification have a "Security Considerations" and "Privacy Considerations" section?
1400-
<dd>Yes, this is the section you are currently reading.
1401-
1402-
<dt>Does this specification allow downgrading default security characteristics?
1403-
<dd>No.
1404-
</dl>
14051356

14061357
<h2 class="no-num non-normative" id="changes">Appendix A. Changes</h2>
14071358

css-contain-2/Overview.bs

Lines changed: 10 additions & 63 deletions
Original file line numberDiff line numberDiff line change
@@ -1988,75 +1988,22 @@ Examples {#cv-examples}
19881988
</div>
19891989

19901990

1991+
<h2 id=privacy oldids="priv-sec">
1992+
Privacy Considerations</h2>
19911993

1994+
There are no known privacy impacts of the features in this specification.
19921995

19931996

1994-
Privacy and Security Considerations {#priv-sec}
1995-
==============================================
1997+
<h2 id=security>
1998+
Security Considerations</h2>
19961999

1997-
This specification introduces no new privacy or security considerations.
2000+
There are no known security impacts of the features in this specification.
19982001

1999-
Like any other CSS specification, it affects the rendering of the document,
2000-
but does not introduce any special ability to present content in a misleading way
2001-
that was not previously available through other CSS modules
2002-
and that isn't inherent to the act of formatting the document.
2002+
Like any other CSS specification, it affects the rendering of the document,
2003+
but does not introduce any special ability to present content in a misleading way
2004+
that was not previously available through other CSS modules
2005+
and that isn't inherent to the act of formatting the document.
20032006

2004-
The <a href="http://www.w3.org/2001/tag/">TAG</a> has developed a <a href="https://www.w3.org/TR/security-privacy-questionnaire/">self-review questionnaire</a>
2005-
to help editors and Working Groups evaluate the risks introduced by their specifications.
2006-
Answers are provided below.
2007-
2008-
<dl>
2009-
<dt>Does this specification deal with personally-identifiable information?
2010-
<dd>No.
2011-
2012-
<dt>Does this specification deal with high-value data?
2013-
<dd>No.
2014-
2015-
<dt>Does this specification introduce new state for an origin that persists across browsing sessions?
2016-
<dd>No.
2017-
2018-
<dt>Does this specification expose persistent, cross-origin state to the web?
2019-
<dd>No.
2020-
2021-
<dt>Does this specification expose any other data to an origin that it doesn’t currently have access to?
2022-
<dd>No.
2023-
2024-
<dt>Does this specification enable new script execution/loading mechanisms?
2025-
<dd>No.
2026-
2027-
<dt>Does this specification allow an origin access to a user’s location?
2028-
<dd>No.
2029-
2030-
<dt>Does this specification allow an origin access to sensors on a user’s device?
2031-
<dd>No.
2032-
2033-
<dt>Does this specification allow an origin access to aspects of a user’s local computing environment?
2034-
<dd>No.
2035-
2036-
<dt>Does this specification allow an origin access to other devices?
2037-
<dd>No.
2038-
2039-
<dt>Does this specification allow an origin some measure of control over a user agent’s native UI?
2040-
<dd>No.
2041-
2042-
<dt>Does this specification expose temporary identifiers to the web?
2043-
<dd>No.
2044-
2045-
<dt>Does this specification distinguish between behavior in first-party and third-party contexts?
2046-
<dd>No.
2047-
2048-
<dt>How should this specification work in the context of a user agent’s "incognito" mode?
2049-
<dd>No difference in behavior is needed.
2050-
2051-
<dt>Does this specification persist data to a user’s local device?
2052-
<dd>No.
2053-
2054-
<dt>Does this specification have a "Security Considerations" and "Privacy Considerations" section?
2055-
<dd>Yes, this is the section you are currently reading.
2056-
2057-
<dt>Does this specification allow downgrading default security characteristics?
2058-
<dd>No.
2059-
</dl>
20602007

20612008
<h2 class="no-num non-normative" id="changes">Appendix A. Changes</h2>
20622009

0 commit comments

Comments
 (0)