# Should the secure context overview be using compat tables?

**URL:** <https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096>\
**Category:** MDN\
**Created:** [May 8, 2019, 7:53pm UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096 "2019-05-08T19:53:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![freaktechnik](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/freaktechnik/32/37766_2.png) [@freaktechnik](https://discourse.mozilla.org/u/freaktechnik)\
**Post date:** [May 8, 2019, 7:53pm UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096/1 "2019-05-08T19:53:54Z")

</div>

I’ve just found this page on MDN: [https://developer.mozilla.org/en-US/docs/Web/Security/Secure\_Contexts/features\_restricted\_to\_secure\_contexts](https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts/features_restricted_to_secure_contexts)

It’s essentially two compat tables, however it currently uses two traditional tables. I understand that this is most likely an issue of being able to generate tables with the required information based on the compat data?

---

<div class="post-metadata">

**Author:** ![exe-boss](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/exe-boss/32/43293_2.png) [@exe-boss](https://discourse.mozilla.org/u/exe-boss)\
**Post date:** [May 8, 2019, 10:27pm UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096/2 "2019-05-08T22:27:43Z")

</div>

Well, some features are&nbsp;only available in&nbsp;secure&nbsp;contexts from the&nbsp;start, which&nbsp;makes them not&nbsp;have the&nbsp;`secure_context_required` sub‑feature, as&nbsp;it’s&nbsp;used only when the&nbsp;implementation version differs from the&nbsp;restricting behind secure context version (the&nbsp;second&nbsp;table).

---

<div class="post-metadata">

**Author:** ![freaktechnik](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/freaktechnik/32/37766_2.png) [@freaktechnik](https://discourse.mozilla.org/u/freaktechnik)\
**Post date:** [May 8, 2019, 10:29pm UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096/3 "2019-05-08T22:29:39Z")

</div>

Shouldn’t that case be detectable based on the version of the browser it was added in, since the secure context policies were introduced at a specific point in the browser release history? Or is the issue that there’d be exceptions?

---

<div class="post-metadata">

**Author:** ![exe-boss](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/exe-boss/32/43293_2.png) [@exe-boss](https://discourse.mozilla.org/u/exe-boss)\
**Post date:** [May 8, 2019, 10:32pm UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096/4 "2019-05-08T22:32:01Z")

</div>

The&nbsp;issue is&nbsp;that there’d be&nbsp;exceptions1 and&nbsp;we&nbsp;can’t just use&nbsp; **BCD** directly for&nbsp;this because&nbsp;of&nbsp;that.

1 Newer secure context only APIs are restricted to&nbsp;secure&nbsp;contexts by&nbsp;default from the&nbsp;get‑go, which means that&nbsp; **BCD** doesn’t include `secure_context_required` as&nbsp;it’s&nbsp;only used when an&nbsp;API is&nbsp;restricted to&nbsp;secure&nbsp;contexts after it&nbsp;has already been shipped.

---

<div class="post-metadata">

**Author:** ![freaktechnik](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/freaktechnik/32/37766_2.png) [@freaktechnik](https://discourse.mozilla.org/u/freaktechnik)\
**Post date:** [May 9, 2019, 8:56am UTC](https://discourse.mozilla.org/t/should-the-secure-context-overview-be-using-compat-tables/40096/5 "2019-05-09T08:56:26Z")

</div>

Right, that’s what I was talking about. There’s a point when browsers decided that new (web) APIs would only be available in secure contexts. Thus there should be a version number, from which all newly added APIs would only be available in secure contexts, thus the list of APIs being everything that was added \>= that version.

I fear that there would still be exceptions to that rule, as in APIs that weren’t added for secure contexts only after that point.
