You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: mediaqueries-5/Overview.bs
+23-12
Original file line number
Diff line number
Diff line change
@@ -3683,23 +3683,14 @@ device-aspect-ratio</h3>
3683
3683
</pre>
3684
3684
</div>
3685
3685
3686
-
<h2 id=priv-sec class=no-num>
3687
-
Appendix B: Privacy and Security Considerations</h2>
3686
+
<h2 id=privacy class=no-num>
3687
+
Appendix B: Privacy Considerations</h2>
3688
3688
3689
3689
<em>This section is not normative.</em>
3690
3690
3691
3691
<div class="non-normative">
3692
3692
3693
-
Issue: this section is incomplete
3694
-
3695
-
The 'display-mode' media feature allows an origin
3696
-
access to aspects of a user’s local computing environment and,
3697
-
particularly when used together with an [=application manifest=][=manifest/display=] member [[APPMANIFEST]],
3698
-
allows an origin some measure of control over a user agent’s native UI.
3699
-
Through a CSS media query, a script can know the display mode of a web application.
3700
-
An attacker could, in such a case,
3701
-
exploit the fact that an application is being displayed in fullscreen
3702
-
to mimic the user interface of another application.
3693
+
Issue: this section is <a href="https://github.com/w3c/csswg-drafts/issues?q=is%3Aopen+is%3Aissue+label%3Amediaqueries-5+label%3Aprivacy-tracker">incomplete</a>
3703
3694
3704
3695
The 'prefers-reduced-data' media feature
3705
3696
may be an undesired source of fingerprinting,
@@ -3715,6 +3706,26 @@ Appendix B: Privacy and Security Considerations</h2>
3715
3706
3716
3707
</div>
3717
3708
3709
+
<h2 id=security class=no-num>
3710
+
Appendix C: Security Considerations</h2>
3711
+
3712
+
<em>This section is not normative.</em>
3713
+
3714
+
<div class="non-normative">
3715
+
3716
+
Issue: this section is <a href="https://github.com/w3c/csswg-drafts/issues?q=is%3Aopen+is%3Aissue+label%3Amediaqueries-5+label%3Asecurity-tracker+">incomplete</a>
3717
+
3718
+
The 'display-mode' media feature allows an origin
3719
+
access to aspects of a user’s local computing environment and,
3720
+
particularly when used together with an [=application manifest=][=manifest/display=] member [[APPMANIFEST]],
3721
+
allows an origin some measure of control over a user agent’s native UI.
3722
+
Through a CSS media query, a script can know the display mode of a web application.
3723
+
An attacker could, in such a case,
3724
+
exploit the fact that an application is being displayed in fullscreen
3725
+
to mimic the user interface of another application.
0 commit comments