Based on discussions form our last Tuesday meeting in January (pre TC39) where we considered feasible ways to securely bootstrap SES realms in the browser, I started refining the requirements for a conceptual implementation in this document: https://www.smotaal.io/experimental/modules/ses-frame
I’d like to share this with the group for insights and to invite anyone interested in joining in on the efforts to connect. I think a concept that avoids the complexities and risks of having any code (privileged or otherwise) actively intercepting every single network request is both theoretically valid and feasible for conforming browsers, avoid unnecessary experimental features (ie aside from iframe.csp(…)
).
Edit: Fixed link glitch