{"url":"https://api.github.com/repos/w3ctag/design-reviews/issues/comments/2982263716","html_url":"https://github.com/w3ctag/design-reviews/issues/1092#issuecomment-2982263716","issue_url":"https://api.github.com/repos/w3ctag/design-reviews/issues/1092","id":2982263716,"node_id":"IC_kwDOAKfwGc6xwbuk","user":{"login":"martinthomson","id":67641,"node_id":"MDQ6VXNlcjY3NjQx","avatar_url":"https://avatars.githubusercontent.com/u/67641?u=adea16237836e526afa569daa66747dacb79c56d&v=4","gravatar_id":"","url":"https://api.github.com/users/martinthomson","html_url":"https://github.com/martinthomson","followers_url":"https://api.github.com/users/martinthomson/followers","following_url":"https://api.github.com/users/martinthomson/following{/other_user}","gists_url":"https://api.github.com/users/martinthomson/gists{/gist_id}","starred_url":"https://api.github.com/users/martinthomson/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/martinthomson/subscriptions","organizations_url":"https://api.github.com/users/martinthomson/orgs","repos_url":"https://api.github.com/users/martinthomson/repos","events_url":"https://api.github.com/users/martinthomson/events{/privacy}","received_events_url":"https://api.github.com/users/martinthomson/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2025-06-18T00:58:15Z","updated_at":"2025-06-18T00:58:15Z","author_association":"CONTRIBUTOR","body":"> Does this address your concerns?\n\nNot really.  At least, not for me personally.  Though the API doesn't get to name a credential, this is new information leakage.  I realize that attempting to read this bit carries the risk of showing prompts that will be very annoying, but I don't see sufficient justification for this.\n\nIf this is for first-time visits to a page or visits from people without any associated identification, as you note, it would be better to have an explicit user choice to log in - engaging the existing flow - rather than have this pop, conditional on there being a credential.\n\nIt seems that the set of cases where a user is unknown to a site, but has a usable credential for that site, is a fairly narrow set of cases.  \n\n* There is obviously the cross-site credentials in Related Origin Requests.  Is that a primary use case?  We haven't established a TAG position on this yet, but we have concerns about cross-site information flow, similar to those for Related Website Sets.\n* A user who has cleared cookies is another potential candidate.  But this design allows for invisible confirmation of a non-recognition, which is undesirable.\n* What else did I miss?\n\nOverall, the information leakage, both through the immediate failure and the API being disabled in private/incognito modes don't seem to be justified by these.","reactions":{"url":"https://api.github.com/repos/w3ctag/design-reviews/issues/comments/2982263716/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"pin":null}