3 ms·
> It'd be cool if the browser used this to allow cross-origin caching as well. As a caveat, there's info leaking here depending on whether the cache hits/misse
by tetrep 10y ago
> It'd be cool if the browser used this to allow cross-origin caching as well.
As a caveat, there's info leaking here depending on whether the cache hits/misses, so this would need to be opt-in from the cache source, e.g. You set up subresource integrity and also say "allow other domains to load this resource from the cache."
Call it subresource sharing?
Edit: opt-in would need to be on both "sides" (sharer and sharee).
- throwaway2048 10y agoThis still wouldnt be enough, because you could still target the unique mix of script/script versions some specific site has, and have a high chance of being accurate, or at least high enough for statistical purposes.
- problems 10y agoGiven the accumulation of scripts from many sites it might work out alright, those specific versions could come from anywhere - not like only 1 site around uses a specific version of jquery or something. It might be enough, but would need testing to prove it out either way.
- tetrep 10y agoWhy is it insufficient? If the site doesn't want to leak that information, it doesn't participate in cache sharing. Since sharing is opt-in, sites won't unknowingly leak this information. Edit: whoops. I see what you mean. I missed an edit while modifying an earlier draft and left the opt-in only on one side, the sharer.