This makes me think that we could use some flag that identifies purely static websites. Like next to the green https lock there is a sign that this website can not send data to any server
This makes me think that we could use some flag that identifies purely static websites. Like next to the green https lock there is a sign that this website can not send data to any server
You'd probably also need some sort of Feature-Policy[3] that prohibits access to any form of persistent storage so sites can't just save data until the next non-CSP-protected page load and transmit it then.
[1]: https://wicg.github.io/webpackage/draft-yasskin-wpack-bundle...
[2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
[3]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Fe...
But even a GET request can be used to send data. Just pack the data you want to send in the query string and voila.
Perhaps the site could be allowed to update itself. But this update function should not have access to any local/client state.