Conversation
|
@jpagnucco to clear the automated ipr check for this and any future contributions, please check that your W3C account is associated with your GH account. That'll fix it. |
|
Hey! Thanks for getting the draft started on this @jpagnucco, been left for a TODO for a while. I like the content here, but now that I'm reading the whole section together, the title and framing feel a bit off. Titling it "violation" feels wrong when most of what's described is the careful design that prevents cross-document exposure without permission. I would prefer to retitle this section to something like "Cross-origin tool exposure" and reorder what you currently slightly have so it leads with the consideration and ends with the residual risk. Roughly:
|
… end with residual risks
victorhuangwq
left a comment
There was a problem hiding this comment.
Thanks for the update, this looks good to me! I cross-checked it against the current spec and I didn't spot any inconsistencies.
@domfarolino tagging you for review and merge.
| </p> | ||
| <ul> | ||
| <li> | ||
| <strong>Direct Cross-Origin Exposure</strong>: Even when two [=origins=] mutually opt in via {{ModelContextRegisterToolOptions/exposedTo}} and {{ModelContextGetToolOptions/fromOrigins}}, they remain separate trust domains: tool providers must still treat caller-supplied arguments as untrusted input, and callers must treat cross-origin tool descriptions and return values as untrusted data (see [[#prompt-injection]]). Additionally, because {{ModelContext/getTools()}} aggregates tools across all descendant frames at the [=origin=] level, callers should inspect {{RegisteredTool/origin}} and {{RegisteredTool/window}} on each {{RegisteredTool}} to disambiguate tools when multiple subframes or [=origins=] expose tools with the same {{RegisteredTool/name}}. |
There was a problem hiding this comment.
This is a good callout.
Summary
Replaces the
TODOplaceholder in Section 6.3.4 (Violation of Same-Origin Boundaries) (#violation-same-origin-boundaries) with documentation covering:getTools()andexecuteTool().allow="tools"): Gated behind the"tools"policy-controlled feature ('self'default allowlist).exposedTo): Explicit allowlisting of potentially trustworthy origins inModelContextRegisterToolOptions.exposedTo.fromOrigins): Explicit opt-in by the caller viaModelContextGetToolOptions.fromOrigins.Preview | Diff