Intent to Prototype: Local network access restrictions for WebTransport

22 views
Skip to first unread message

Chromestatus

unread,
1:28 PM (10 hours ago) 1:28 PM
to blin...@chromium.org, cth...@chromium.org, jdeb...@chromium.org, hc...@chromium.org
Contact emails
hc...@chromium.org

Explainer
https://github.com/WICG/local-network-access/blob/main/explainer.md

Specification
https://wicg.github.io/local-network-access/#integration-with-webtransport

Summary
Restricts the ability to make requests to the user's local network using WebTransport, gated behind a permission prompt. A local network request is any request from a public website to a local IP address or loopback, or from a local website (e.g. intranet) to loopback. Gating the ability for websites to perform these requests behind a permission reduces the ability of sites to use these requests to fingerprint the user's local network. This permission is restricted to secure contexts. This work is adding to the Local Network Access Restrictions work here: https://chromestatus.com/feature/5152728072060928

Blink component
Blink>SecurityFeature>LocalNetworkAccess

Web Feature ID
local-network-access

Motivation
Local WebTransport connections are subject to many of the same attacks that the original LNA proposal are designed to solve. This would add the same controls that were implemented in the original LNA proposal to WebTransport

Initial public proposal
None

TAG review
None

TAG review status
Pending

Risks


Interoperability and Compatibility
None

Gecko: No signal

WebKit: No signal

Web developers: No signals

Other signals:

WebView application risks

Does this intent deprecate or change behavior of existing APIs, such that it has potentially high risk for Android WebView-based applications? None



Debuggability
None

Is this feature fully tested by web-platform-tests?
No

Flag name on about://flags
None

Finch feature name
None

Non-finch justification
None

Requires code in //chrome?
False

Tracking bug
https://issues.chromium.org/issues/421216834

Estimated milestones

No milestones specified



Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/5126430912544768?gate=5462429895098368

This intent message was generated by Chrome Platform Status.
Reply all
Reply to author
Forward
0 new messages