| @@ -33,11 +33,11 @@ | ||
| 33 | 33 | ## Cross-origin isolation / `SharedArrayBuffer` |
| 34 | 34 | |
| 35 | 35 | WASM-based image optimization requires `SharedArrayBuffer` support, which in turn requires [cross-origin isolation](https://web.dev/articles/cross-origin-isolation-guide). |
| 36 | 36 | |
| 37 | -This is achieved using the [`Document-Isolation-Policy`](https://github.com/nicolo-ribaudo/tc39-proposal-structs/blob/main/test262-filtering/isolation-explainer.md) header, which provides per-document cross-origin isolation without affecting other iframes on the page. This avoids the breakage that the older `Cross-Origin-Embedder-Policy` / `Cross-Origin-Opener-Policy` headers caused for third-party plugins and embeds. | |
| 37 | +This is achieved using the [`Document-Isolation-Policy`](https://github.com/WICG/document-isolation-policy) header, which provides per-document cross-origin isolation without affecting other iframes on the page. This avoids the breakage that the older `Cross-Origin-Embedder-Policy` / `Cross-Origin-Opener-Policy` headers caused for third-party plugins and embeds. | |
| 38 | 38 | |
| 39 | -Once the page is served with this header, `SharedArrayBuffer` will be available in the browser, and WASM-based image optimization will work as expected. All embedded resources (e.g., images, scripts) are served with `crossorigin="anonymous"` to ensure cross-origin isolation is maintained. | |
| 39 | +Once the page is served with this header, `SharedArrayBuffer` will be available in the browser, and WASM-based image optimization will work as expected. Embedded resources from other origins (images, scripts, styles, audio, video) keep loading without a `crossorigin` attribute, because `isolate-and-credentialless` loads them without credentials instead of blocking them. | |
| 40 | 40 | |
| 41 | 41 | ### Troubleshooting |
| 42 | 42 | |
| 43 | 43 | If client-side media processing is not working, check the browser console for messages. Common issues include: |