New Security Considerations #1618
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Resolves #1231
Replaces #1600
This is a full rewrite of the Security Considerations sections of the Core spec. It retains most of the original content plus a lot more. The only thing I left out from the original is the part about
$comment
, which I don't think makes sense. If there's an argument for keeping it, I can add it back in.This new Security Consideration section is inspired by the guidelines and examples in RFC 3552 - Guidelines for Writing RFC Text on Security Considerations. Some principles I'm trying to follow are,
Something worth mentioning is that this PR advises not to use
file:
URIs in$id
. However, we use file URIs in a couple tests in the official test suite. We should consider changing, removing, or moving those tests to optional.