6 ms·
The same could be said of any CDN hosted javascript library. For example: jquery. There is an open intent to implement support for publishers self-hosting the A
by gregable 6y ago
The same could be said of any CDN hosted javascript library. For example: jquery. There is an open intent to implement support for publishers self-hosting the AMP library as well.
- ComputerGuru 6y agoYou missed the required part.
- donaltroddyn 6y agoFor most JS served by CDN, you can (and should) use Subresource Integrity to verify the content. At least the last time I was involved in an AMP project, Google considered AMP to be an "evergreen" project and did not allow publishers to lock in to a specific version.
- gregable 6y agoLong term versions are now supported, so publishers can lock in a specific version. Publisher hosted copies are in the pipeline, as I referenced in the parent comment. My choice of verbiage was a bit confusing it appears.
- donaltroddyn 6y agoI don't think it's your wording that's confusing. You are contradicting the AMP documentation. AMP's documentation seems to indicate that the LTS is stable only for one month (new features released via the same URL each month), and so is not compatible with SRI (see https://github.com/ampproject/amphtml/blob/master/contributing/lts-release.md https://github.com/ampproject/amphtml/blob/master/contributi...) You can specify a version (ie, https://cdn.ampproject.org/rtv/somenum/v0.js https://cdn.ampproject.org/rtv/somenum/v0.js), but the AMP validator complains about that.
- WA 6y ago> The same could be said of any CDN hosted javascript library Yes, and? What’s your point? It’s actually a security weakness to include third party JS. The whole thing runs on trust.
- gowld 6y agoWhat's an open intent? Where is this documented?
- tyingq 6y agoAMP spec: https://amp.dev/documentation/guides-and-tutorials/learn/spec/amphtml/ https://amp.dev/documentation/guides-and-tutorials/learn/spe... "AMP HTML documents MUST..." "The AMP runtime is loaded via the mandatory <script src="https://cdn.ampproject.org/v0.js"></script> https://cdn.ampproject.org/v0.js"></script> tag in the AMP document <head>." Do a whois on ampproject.org: "Registrant Organization: Google LLC Registrant State/Province: CA Registrant Country: US Admin Organization: Google LLC" Note that jQuery, as mentioned in some GP comment has no such requirement. Google AMP is quite unique in this regard. This is NOT some general CDN type issue. Also...agreed, WTF is "open intent"?
- gregable 6y agohttps://github.com/ampproject/amphtml/issues/25873 https://github.com/ampproject/amphtml/issues/25873