WebPerfWG call - January 19th 2023

Participants

Michal Mocny, Sia Karamalegos, Pat Meenan, Dan Shappir, Ian Clelland, Barry Pollard, Alex N. Jose, Annie Sullivan, Katie Sylor Miller, Michelle Vu, Nic Jansma, Yoav Weiss, Lucas Pardue, Steven Bougon, Carine Bournaz, Hao Liu, Lan Wei, Abin Paul, Rafael Lebre

Minutes

LCP and image entropy - Ian Clelland

Recording

Resource Timing and Basic Auth - Nic Jansma

Google Chat Log

Nic Jansma7:06 PM

https://github.com/w3c/resource-timing/issues/340

Sia Karamalegos7:10 PM

CHAOS

Benjamin De Kosnik7:30 PM

..... why moz wanted paint timing in interop 2023

Dan Shappir7:30 PM

Any browsers other than Chromium-based even implement LCP as all?

Sean Feng7:31 PM

Firefox is implementing it

Michal Mocny7:32 PM

huzzah

Benjamin De Kosnik7:32 PM

i hear you Michal, know you are/were working towards this

Sia Karamalegos7:33 PM

yeah one of those looked like the cloudinary logo

Michal Mocny7:35 PM

Ben/Sean, Noam's also been thinking about animation frames and timing as he's been looking at Long Task attribution (I know, a bit out of left field).  Would be good to still sync with you folks on the content of that interop proposal even if it wasn't selected.  Maybe a future wg meeting

Dan Shappir7:35 PM

I love the Web! :-D

Ian Clelland7:36 PM

Thanks for the discussion, everyone!

Benjamin De Kosnik7:37 PM

Michal, yes. It would have been easier for us if it was selected but we are trying to negotiate doing it anyway. In progress... ping after FOSDEM in email?

Ian Clelland7:38 PM

I would like to vote for killing this with fire.

Sia Karamalegos7:41 PM

or redact that part of the url

Patrick Meenan7:42 PM

My vote is to strip credentials from all RT urls

Nic Jansma7:43 PM

https://github.com/w3c/resource-timing/issues/7

Benjamin De Kosnik7:43 PM

agree with Patrick

Marcel Duran7:44 PM

Sia, check it out Yoav's article: https://calendar.perfplanet.com/2018/how-the-sausage-is-made-webperfwg-meeting-summary/

Sia Karamalegos7:44 PM

Thanks, Marcel!

Benjamin De Kosnik7:47 PM

what is the status with fetch and disallowing this

Patrick Meenan7:51 PM

FWIW, fetch spec still allows username and pw in URLs: https://url.spec.whatwg.org/#concept-url

Benjamin De Kosnik7:52 PM

thanks

Patrick Meenan7:52 PM

Serializing a response URL for reporting looks like it strips it out: https://fetch.spec.whatwg.org/#serialize-a-response-url-for-reporting

So there is precedence for stripping auth from the URLs for reporting

Barry Pollard7:53 PM

Both!

Sia Karamalegos7:55 PM

Should we ask a security expert? Because knowing the username gets you much closer to being able to log in

Michal Mocny7:57 PM

My source is very authoritative, I found notes on wikipedia LOL

Steven Bougon7:58 PM

:-)

Sia Karamalegos7:58 PM

for optics

Katie Sylor-Miller7:59 PM

thanks all!

Michelle Vu (She Her)7:59 PM

thanks!