Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-27 Thread Mike Taylor
LGTM3 On 6/28/23 2:06 AM, Stephen Mcgruer wrote: Thanks Mustaq for your input (and API OWNERS for the ongoing LGTMs, here's hoping for #3 :)). I agree with your points on the difficulty of making either user activation or capability delegation work across navigation (though I still personally

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-27 Thread Stephen Mcgruer
Thanks Mustaq for your input (and API OWNERS for the ongoing LGTMs, here's hoping for #3 :)). I agree with your points on the difficulty of making either user activation or capability delegation work across navigation (though I still personally think there are reasonable use-cases! :D). We're

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-27 Thread Yoav Weiss
LGTM2 conditional on the PR landing On Mon, Jun 26, 2023 at 5:02 PM Rick Byers wrote: > This makes good sense to me. Obviously there's so much risk and potential > for abuse around payments, getting the user to click seems like a very weak > mitigation anyway (eg. the prevalence of "click to

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-26 Thread Rick Byers
This makes good sense to me. Obviously there's so much risk and potential for abuse around payments, getting the user to click seems like a very weak mitigation anyway (eg. the prevalence of "click to read more" buttons). +1 to waiting for the PR to land, but it looks like the WG has now approved

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-22 Thread Mustaq Ahmed
Hi Stephen: Your summary is correct: determining how much "remaining time" to carry over a navigation is an unanswered question for user activation here but more importantly, carrying even a few milliseconds across a navigation is prone to abuse. For example, imagine accidentally clicking on an

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-19 Thread Stephen Mcgruer
> Have y'all considered passing along the user activation from the redirector page to the redirected page? (maybe with an explicit opt-in from the redirector) We looked at that approach early, and discussed it with mustaq@ (cc'd) who has worked on a lot of user activation V2. Specifically, the

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-19 Thread Yoav Weiss
Thanks Stephen! :) On Mon, Jun 19, 2023 at 3:13 PM Stephen Mcgruer wrote: > Hi Yoav, thanks for the questions! > > > The PR seems to be a draft. What's preventing us from landing it? Was > this discussed in some public forum? > > We intend to land the PR before shipping this feature. It has

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-19 Thread Stephen Mcgruer
Hi Yoav, thanks for the questions! > The PR seems to be a draft. What's preventing us from landing it? Was this discussed in some public forum? We intend to land the PR before shipping this feature. It has been discussed broadly in the Web Payments WG, but I expect to raise the specific PR for

Re: [blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-14 Thread Yoav Weiss
On Tue, Jun 13, 2023 at 8:54 PM Nick Burris wrote: > Contact emailsnbur...@chromium.org, smcgr...@chromium.org, > i...@chromium.org > > Specificationhttps://github.com/w3c/payment-request/pull/1009 > The PR seems to be a draft. What's preventing us from landing it? Was this discussed in some

[blink-dev] Intent to Implement and Ship: Remove Payment Request User Activation Requirement

2023-06-13 Thread Nick Burris
Contact emailsnbur...@chromium.org, smcgr...@chromium.org, i...@chromium.org Specificationhttps://github.com/w3c/payment-request/pull/1009 Design docs https://docs.google.com/document/d/16DHqqPWe5oM6Rucnn6Y1llhJ-DoEeLtTWFldJFg4iqA/edit#heading=h.w5782xqp7ab4 Summary To help developers reduce