Re: WebAPI Security Discussion: Contacts API

2012-06-03 Thread Paul Theriault
Final call for comment/changes to the permissions model for this API. Please provide comment (to dev-weba...@lists.mozilla.org only) by COB Monday June 4. I've tried to incorporate feedback so far, though note that this post is really mainly about deciding which app types will be explicit, an

WebAPI Security Discussion: Contacts API

2012-04-26 Thread Lucas Adamski
Name of API: Contacts API Reference:https://wiki.mozilla.org/WebAPI/ContactsAPI Brief purpose of API: Access to users contacts. General Use Cases: Inherent threats: Access to confidential information, destroy user's data, upload contacts to site. Denial of service by filling storage or obscuri