outer.example
userN.inner.example
shared.example/resource
Since, as you say, outer.example could load the shared resources and postMessage them into userN.inner.example, it does seem to me like there should be a way for outer.example and userN.inner.example to opt into letting userN.inner.example use the outer.example cache partition.Have you considered raising a spec issue?
I don't see any good way of enabling a target origin to opt into allowing source origins to share caches with it, that wouldn't also reintroduce the privacy leaks. (As, after all, even if the only things malicious-site-X can see in your cache are ad-tech providers' origins that opted into allowing anyone to interface with them, that's likely still enough to fingerprint you.)
Just so I understand it correctly: * The iframe loads resources, e.g. /static/bundle.js and /public/index.css (does this include user-defined resources?). * But due to the iframe being embedded on sub**.framercanvas.com, the cache key includes the subdomain. So all resources are fetched again for all projects?
Is there a large enough audience visiting multiples sites that would make the effort worth it?
Your website runs terribly on firefox. Multiple hundred-of-millisecod periods where the viewport went blank.