Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Two changes to Secure Payment Confirmation prior to CR #802

Closed
ianbjacobs opened this issue Jan 11, 2023 · 3 comments
Closed

Two changes to Secure Payment Confirmation prior to CR #802

ianbjacobs opened this issue Jan 11, 2023 · 3 comments
Assignees
Labels
privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. Resolution: satisfied The TAG is satisfied with this design Review type: small delta Topic: payments Venue: Web Payments WG

Comments

@ianbjacobs
Copy link

Wotcher TAG!

I'm requesting a TAG review of Secure Payment Confirmation (SPC) based on two non-editorial changes to the specification since the previous TAG review that was conducted as we approached CR:
#675

Since that review, the Web Payments Working Group has made or plans to make two non-editorial changes to the specification. We seek your review of these changes as we prepare to go to CR:

  • The addition of an opt-out feature, requested by developers to help satisfy GDPR requirements. For background, see issue 172 and the resulting changes to the specification. Experimentation with this feature has demonstrated its utility to at least one organization that has experimented with SPC.
  • The expected removal of a requirement that the user agent consume a user activation during authentication. For background, see issue 216, including the Chrome Team's security and privacy consideration notes. Although we have not yet updated the specification to remove the user activation requirement, we seek your review at this time. We would anticipate the actual change to the specification to be small (and it would include the security and privacy considerations).

Further details:

  • [✅] I have reviewed the TAG's Web Platform Design Principles
  • Relevant time constraints or deadlines: Review ideally by 1 February 2023.
  • The group where the work on this specification is currently being done: Web Payments Working Group
  • Major unresolved issues with or opposition to this specification: None at this time.

We'd prefer the TAG provide feedback as (please delete all but the desired option):

🐛 open issues in our GitHub repo for each point of feedback

@plinss plinss changed the title Request for review of two changes to Secure Payment Confirmation prior to CR Two changes to Secure Payment Confirmation prior to CR Jan 30, 2023
@maxpassion maxpassion self-assigned this Jan 31, 2023
@torgo
Copy link
Member

torgo commented Feb 8, 2023

Hi @ianjacobs - this change looks good to us. Thanks for running this by us and thanks to the group for documenting this so well in the issue including the security & privacy considerations and potential abuse cases. We would encourage you to document this in the explainer and in the spec as well and to provide some additional guidance to UA developers about the risks and mitigations.

In particular, we were very happy to see the group ask for us to weigh in on last minute changes; given that there isn't anything mandating this in the process.

We wish you luck with this. Please let us know if we can help with anything else.

@torgo torgo closed this as completed Feb 8, 2023
@torgo torgo added Resolution: satisfied The TAG is satisfied with this design Review type: small delta privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. and removed Progress: unreviewed labels Feb 8, 2023
@ianbjacobs
Copy link
Author

@torgo, thank you and the TAG for the review and the support! I will work with the editors to integrate guidance for developers as you recommend.

@ianbjacobs
Copy link
Author

@torgo, we have merged our pull request into the explainer as suggested.
https://github.com/w3c/secure-payment-confirmation/blob/main/explainer.md

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. Resolution: satisfied The TAG is satisfied with this design Review type: small delta Topic: payments Venue: Web Payments WG
Projects
None yet
Development

No branches or pull requests

5 participants