Skip to content

WIP: Add LWS threat model document#202

Open
renyuneyun wants to merge 6 commits into
w3c:mainfrom
renyuneyun:threat-model
Open

WIP: Add LWS threat model document#202
renyuneyun wants to merge 6 commits into
w3c:mainfrom
renyuneyun:threat-model

Conversation

@renyuneyun

@renyuneyun renyuneyun commented Jul 17, 2026

Copy link
Copy Markdown

Work In Progress
Creating this PR to get discussion going.

[preview]

Info

Initial threat model covering three threats:

  • T1: Injected Identity Providers
  • T2: Impersonation Through Credentials
  • T3: Client ID Impersonation

More to be added.

Question

Based on the respec-threats rendering library (Apache 2.0). Does that have any copyright issues with LWS Spec when it comes to maturity?

Initial threat model covering three threats:
- T1: Injected Identity Providers
- T2: Impersonation Through Credentials
- T3: Client ID Impersonation

Based on the respec-threats rendering library (Apache 2.0).
@renyuneyun renyuneyun mentioned this pull request Jul 17, 2026
1 task
@elf-pavlik

elf-pavlik commented Jul 17, 2026

Copy link
Copy Markdown
Member

Awesome @renyuneyun 🎉

I'm going to add few more things to this PR branch tomorrow. @acoburn can we allocate 5 min on Monday to introduce this work during the WG call? We could also use some pointers to how PR previews are setup for this repo.

Based on the respec-threats rendering library (Apache 2.0). Does that have any copyright issues with LWS Spec when it comes to maturity?

That lib/template already has an issue to track it moving to W3C github org

Comment thread threat-model/index.html Outdated
Data Flow Diagram for LWS Threat Model
</h3>
<figure id="lws-threat-model">
<img height="1890" src="minimalist-web-threat-model.png"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@acoburn

acoburn commented Jul 17, 2026

Copy link
Copy Markdown
Member

A preview of this document is at https://htmlpreview.github.io/?https://github.com/renyuneyun/lws-protocol/blob/threat-model/threat-model/index.html

We will want to adjust the formatting to bring it in line with W3C conventions

- T2: changed affected elements to P3, P4, P5
- T3: revised threat description and responses, changed elements to P3, P2
@renyuneyun

renyuneyun commented Jul 18, 2026

Copy link
Copy Markdown
Author

A preview of this document is at ...

Thanks @acoburn for having the preview. But... It appears the preview only included the html, without css and js? That leads to incorrect rendering, and incomplete content (of the threats, which are based on js).

@elf-pavlik

elf-pavlik commented Jul 18, 2026

Copy link
Copy Markdown
Member

This one seems to work better: https://raw.githack.com/renyuneyun/lws-protocol/threat-model/threat-model/index.html
@renyuneyun can you please add it to the original description for at the top?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants