Please consider whether new APIs/functionality should be disabled by default in sandboxed iframes

2017-01-11 Thread Boris Zbarsky
When adding a new API or CSS/HTML feature, please consider whether it should be disabled by default in sandboxed iframes, with a sandbox token to enable. Note that this is impossible to do post-facto to already-shipped APIs, due to breaking compat. But for an API just being added, this is a

Re: Please consider whether new APIs/functionality should be disabled by default in sandboxed iframes

2017-02-27 Thread David Bruant
Hi Boris, Did a particular feature triggered your message? Would it make sense to add the question to the "Intent to Implement" email template? https://wiki.mozilla.org/WebAPI/ExposureGuidelines#Intent_to_Implement "Intent to" emails seem like a good time to ask this questions/raise: * the feat

Re: Please consider whether new APIs/functionality should be disabled by default in sandboxed iframes

2017-02-27 Thread Boris Zbarsky
On 2/27/17 7:07 AM, David Bruant wrote: Did a particular feature triggered your message? No, it was just something I had been thinking about for a bit. Would it make sense to add the question to the "Intent to Implement" email template? https://wiki.mozilla.org/WebAPI/ExposureGuidelines#Inte