Comments (6)
see note about each resource having its HEADER+BODY signed in : https://github.com/dimich-g/webpackage/blame/master/README.md#L308
My PR rephrased in a few places to make more explicit in #23
It might be prudent however to change the phrasing of https://github.com/dimich-g/webpackage/blame/master/README.md#L312 to state that nested packages as signed as opaque entities as it sounds currently like nested packages are not something that the root package can verify as being correct currently.
from webpackage.
Just noticed, the certificates are not signed in the Content-Index examples; unsure if this is intentional, but seems like just an accident.
from webpackage.
@lrosenthol if certificates are signed is the rest covered?
from webpackage.
from webpackage.
Arguably, these details can go in the draft specification rather than the explainer, but it's probably time to start that specification and add these details, so we can iterate on them.
from webpackage.
#36 now specifies exactly which bytes are hashed and signed, so I believe this is fixed.
from webpackage.
Related Issues (20)
- Path prefix? HOT 1
- Registered protocol handlers HOT 4
- Update <top_dir>/README.md to mention "Subresource Loading with WebBundles" spec HOT 1
- Subverting path-based CSP HOT 2
- Improve relative URLs support in Go/JavaScript bundle tools HOT 1
- Clarify how `<script type=webbundle>` affects speculative HTML parsing. HOT 1
- Chromium error when loading minimal wbn: Cannot parse the size of section-lengths HOT 6
- [subresource-loading] Update the spec to reflect the upstream changes of HTML.
- Is primaryURL still required on b2? HOT 10
- Web Bundles that don't have an origin? HOT 3
- Secure Context in bundles that don't have an origin? HOT 6
- webpackage maybe solve this WIGC problem: Integrating websites with the browser
- Alternate SignedExchange prefetch and CORS
- Improving instructions for generating bundle from local directory HOT 1
- Distributing service worker script via SXG
- Function signature change: reading all bytes from a stream
- Convert from zip to web pack / bundle format online
- go/bundle explain how to use gzip with this HOT 1
- go/bundle includes hidden .git files by default HOT 2
- issue HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from webpackage.