-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
add bubbleapps.io and cdn.bubble.io to public_suffix_list.dat #2380
Conversation
|
Have you considered implementing |
We are currently exploring _Host as well. The team has decided that we would also want to add our domains to PSL as an additional security measure. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Public Suffix List (PSL) Submission
Checklist of required steps
Description of Organization
Robust Reason for PSL Inclusion
DNS verification via dig
Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration, and we shall keep the
_psl
TXT record in place in the respective zone(s).Submitter affirms the following:
Abuse Contact:
Abuse contact information (email or web form) is available and easily accessible.
URL where abuse contact or abuse reporting form can be found:
Please report directly to [email protected]
For PRIVATE section requests that are submitting entries for domains that match their organization website's primary domain, please understand that this can have impacts that may not match the desired outcome and take a long time to rollback, if at all.
To ensure that requested changes are entirely intentional, make sure that you read the affectation and propagation expectations, that you understand them, and confirm this understanding.
PR Rollbacks have lower priority, and the volunteers are unable to control when or if browsers or other parties using the PSL will refresh or update.
(Link: about propagation/expectations)
Description of Organization
Bubble.io is a no-code platform for building web applications using a visual editor, workflow automation, and a built-in database. It supports API integrations, user authentication, and plugins for extended functionality. Applications are hosted and scaled on Bubble's infrastructure. It is used for developing web apps, marketplaces, business tools, etc without writing traditional code.
I am a software engineer on Bubble's platform team.
Organization Website:
https://bubble.io/
Reason for PSL Inclusion
Adding bubble.io and bubbleapps.io to the Public Suffix List would ensure that subdomains like app1.bubbleapps.io and app2.bubbleapps.io are treated as separate entities, ensuring cookies separation and cross-app security risks such as session hijacking. This is crucial for Bubble.io as a multi-tenant platform, where different users create apps under the same domain.
Number of users this request is being made to serve:
Estimated 4.7 million
DNS Verification