Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Message from discussion One-app-per-origin
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Jonas Sicking  
View profile  
 More options May 3 2012, 7:39 pm
Newsgroups: mozilla.dev.webapps
From: Jonas Sicking <jo...@sicking.cc>
Date: Thu, 3 May 2012 16:39:54 -0700
Local: Thurs, May 3 2012 7:39 pm
Subject: Re: One-app-per-origin

On Tue, Apr 17, 2012 at 9:21 AM, Robert Kaiser <ka...@kairo.at> wrote:
> Benjamin Smedberg schrieb:

>> Why? Having multiple apps per domain doesn't change the scope of the
>> permissions, which would still be the origin (standard web security
>> model).

> Whoa, so let's says Google Maps would get full access to my contacts and my
> camera just because I gave one of those permissions to Google+ and one to
> Google Talk and all of them share a google.com/ origin? I wouldn't expect
> that, to be honest.

No. The google maps app wouldn't need to get access to your camera
just because you granted google+ that access.

However, practically speaking, when you grant access to an app for
something, you are generally actually granting the developers of that
app that access. I.e. if you install angry birds and grant it access
to your camera, you are actually granting Rovio (the angry birds
developers) access to your camera.

And so in the example above, while the google maps app wouldn't have
camera access, the google+ app could likely use any of the scripts or
other resources from google maps. And so if you don't trust google
with camera access, you likely shouldn't grant it to google+.

/ Jonas


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.