Elektrine lite

← Feed

@owen@mastodon.transneptune.net

Post #2271392

2026-05-08 23:25 UTC

Do you want to put a web page on a .local address to do something cool for your household or club? Here's the list of browser features that browser vendors have decided you're just not fuckin' allowed to use. https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Secure_Contexts/features_restricted_to_secure_contexts Some random site halfway around the world, served over https with a robo-verified certificate, is allowed, though, so take some comfort in that.

Replies (3)

  • There's a discussion thread about allowing RFC 1918 addresses and their ip6 equivalents to participate in secure contexts at https://github.com/w3c/webappsec-secure-contexts/issues/60 . It is _eight years_ old without resolution. I can't find any discussion at all on allowing the user to designate certain origins as secure contexts. Maybe that's a thing for some browsers.

    Open ##2563453

  • I really - honestly - want to know what the rationale is for _gamepad APIs_ being on that list.

    Open ##2563455

  • @jaharmi@fosstodon.org @owen@mastodon.transneptune.net And load the root cert into every device in the LAN including guests? (See mention of "club" in first post)

    Open ##2563481