You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

主流浏览器中W3C Geolocation API用户授权有效期查询及规范建议符合性验证

Geolocation API User Authorization Expiry: Major Browser Behavior

Hey there, let's dive into your questions about how major browsers handle permission expiry for the W3C Geolocation API, including alignment with the spec's recommendations:

1. Authorization Expiry Durations Across Browsers

Here's a detailed breakdown of each major browser's permission expiry options:

  • Chrome & Edge:

    • Allow once: Expires as soon as you close the tab or navigate away from the site (strict single-page session).
    • Allow while using the site: Expires when you close the entire browser (persists across tab reloads in the same browser session).
    • Allow all the time: Permanent access until you manually revoke it in browser settings.
      The default prompt highlights "Allow while using the site," but the single-session option is available.
  • Firefox:

    • Default option: Allow for Session – permission expires when you close the browser (or the specific tab, depending on context).
    • Additional options: Allow Always (permanent until revoked) and Block.
      Firefox sticks closely to the spirit of the spec's session-based default.
  • Safari:

    • Desktop: Defaults to Allow for One Day (time-based expiry, 24 hours) alongside Deny. Users can manually set Allow Always in settings.
    • Mobile (iOS/iPadOS): Defaults to Allow While Using App (expires when you exit Safari) and Allow Once (expires after the current session), plus Deny. Mobile Safari's core option aligns with session-based expiry, but desktop uses a time window instead.

2. Compliance with W3C Spec's Single-Session Default

The W3C Geolocation API spec (Section 3.1) recommends user agents default to limiting permission expiry to a single browsing session. Here's how each browser measures up:

  • Firefox: Fully compliant – its default permission is session-limited, expiring when the browser closes.
  • Chrome & Edge: Partially compliant. They offer the spec-recommended single-session "Allow once" option, but their default prompt prioritizes the longer "Allow while using the site" (browser-wide session) instead of strict single-page session expiry.
  • Safari (Desktop): Not compliant with the single-session default. Its default is a 24-hour time-based expiry rather than session-limited. Mobile Safari, however, defaults to a session-aligned "Allow While Using App" option.

From W3C Geolocation API Spec Section 3.1:
"End users typically grant permission explicitly via a user interface that often presents a range of permission expiry options to choose from. Different user agents have different expiry options, common types include time-based (e.g., "one day"), until the browser is closed, and possibly an option to grant permission permanently. While user agents may vary in the granularity of permission expiry, this specification recommends that user agents default to limiting permission expiry to a single browsing session (see the normative requirement in Section 3.4 "Checking API Usage Permissions")."

内容的提问来源于stack exchange,提问作者Thomas Domingues

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 18:42:38