Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support FedCM-based grants #196

Open
johannhof opened this issue Feb 22, 2024 · 1 comment
Open

Support FedCM-based grants #196

johannhof opened this issue Feb 22, 2024 · 1 comment

Comments

@johannhof
Copy link
Member

In the FedID CG we have been discussing the merits of autogranting Storage Access calls based on existing FedCM grants. Based on the positive reception of this idea we wrote up an explainer of how we think this should work from a technical perspective: https://github.com/explainers-by-googlers/storage-access-for-fedcm

Relevant for this specification is that instead of simply creating a new storage-access permission on a successful FedCM prompt, we'd update Storage Access to look at existing FedCM accounts connections to establish whether storage access can be granted without an additional prompt. Benefits to this include the ability to scope the grant to the privacy boundaries of FedCM, and avoiding two simultaneous permission grants for the user (agent) to manage.

This issue is tracking discussion and integration on the Privacy CG side.

cc @bvandersloot-mozilla @annevk

@johannhof johannhof added the agenda+ Request to add this issue to the agenda of our next telcon or F2F label Feb 22, 2024
@martinthomson martinthomson removed the agenda+ Request to add this issue to the agenda of our next telcon or F2F label May 2, 2024
@martinthomson
Copy link

This was discussed at the last meeting and the conclusion was that there was interest, but we'd need to establish that enough implementations were prepared to deploy this. I think that we have those indications, but we will confirm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants