Thomas Steiner (@tomayac)

Hamburg, Germany

The below is an off-site archive of all tweets posted by @tomayac ever

June 27th, 2020

@jho_crypto Yepp, happy this tip helped. 😃 If you want to (or can) share what you’re working on, I’d be curious to have a look.

via Twitter for iPhone in reply to jho_crypto

@firt Yes, I was more focusing on what this entitlement entitles you to do. Service workers, caching,… maybe even something else?

via Twitter for iPhone in reply to firt

Improving HTTP with structured header fields, by @mnot: fastly.com/blog/improve-h….

via Echofon

@nekrtemplar @firt FWIW, I looked into Facebook’s Android WebView, which is marked as debuggable now: blog.tomayac.com/2019/12/09/ins…. It seemed clean when I tested, at least when it comes to injected JavaScript.

via Echofon in reply to nekrtemplar

@firt Great digging, thanks. Only catching up now. Weird that the blog post wouldn’t mention service workers. Also still no details on the com.apple.developer.web-browser entitlement. Altogether sounds like a promising step in the right di

via Echofon in reply to firt

@_alastair @firt @othermaciej The big question mark are still the entitlement details: nothing much to be found right now apart from the @webkit blog post and @firt’s thread: google.com/search?q=%22en…. The entitlements documentation still doesn’t mentiodeveloper.apple.com/documentation/…

via Echofon in reply to _alastair

johnwilander App-bound domains – a new way to restrict potentially privacy-invasive WebView APIs to web content from a specific set of domains while protecting the rest of the webwebkit.org/blog/10882/app…qX This post also provides details for how to enable the new ITP setting in WKWebView.

via Twitter Web App (retweeted on 11:34 AM, Jun 27th, 2020 via Echofon)

@jho_crypto The API was renamed: github.com/WICG/video-rvf…. You can’t really get frame-accuracy, but check the presentationTime in the metadata: wicg.github.io/video-rvfc/#do…

via Twitter for iPhone in reply to jho_crypto