add t3.storage.dev, t3.storageapi.dev for tigrisdata.com#2818
add t3.storage.dev, t3.storageapi.dev for tigrisdata.com#2818bocao-tigris wants to merge 1 commit intopublicsuffix:mainfrom
Conversation
86d150e to
bbbc212
Compare
|
@bocao-tigris Are you sure you want that wildcard? For example if |
Per PSL Guidelines, this is a non-acceptance:
Please note: The #PRIVATE section comes from the public (irony noted). There should zero trust or security assumptions made about these entries.https://github.com/publicsuffix/list/wiki/Third-Party-Diffusion |
bbbc212 to
cd8c098
Compare
cd8c098 to
939bec4
Compare
Thank you for pointing out the misunderstanding regarding wildcard entries. Let me clarify the hosting model and intended Public Suffix boundary. We operate a multi-tenant object storage platform under storage.dev. Customers are mutually untrusted parties and can serve arbitrary web-accessible content from these subdomains, including static websites and application assets. Without a Public Suffix List entry at t3.storage.dev, browsers compute the registrable domain as t3.storage.dev. This would allow one tenant to set cookies scoped to the parent domain and potentially interfere with other tenants’ applications hosted on sibling subdomains. Adding t3.storage.dev to the Public Suffix List would ensure that each customer subdomain is treated as an independent site boundary by browsers, aligning browser security behavior with the platform’s ownership and trust model. I've also updated the entry to t3.storage.dev and t3.storageapi.dev |
|
Question (upon some simple checks):
|
|
Hi @pencilnav let me explain. We provide a S3-compatible object storage service which means we provide the same features as S3 and follow the same conventions. https://t3.storage.dev is the S3-compatible endpoint that is used to access the object storage service. Furthermore, virtual host style URLs are the default way of referencing objects in a bucket. In a virtual-hosted–style URI, the bucket name is part of the domain name in the URL. Virtual-hosted–style URLs use the following format: Here are some live URLs of buckets: With regards to the IP addresses, you probably meant |
|
@ovaistariq Please answer all of the questions. |
|
Thanks for the follow-up. Addressing each question: User counts:We have millions of active buckets across Active subdomain evidence (verifiable):You can validate this resolves and serves content. oracle.storage.dev / oracle.storageapi.dev:These are internal infrastructure domains. IP address concernt3.storage.dev does not resolve to |
|
The _psl records were pointing to the older PR. I have fixed them now. Could you please re-run the CI job. |
|
Related: #2632 |
|
@pencilnav Is there anything else you need from us to accept the PR? |
|
@bocao-tigris Your domain needs to be renewed.
HTTP Redirects to an abuse reporting page or company site with abuse report contact should also be implemented for |
|
thanks, we're working on that |

Public Suffix List (PSL) Submission
Checklist of required steps
Description of Organization
Robust Reason for PSL Inclusion
DNS verification via dig
Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration, and we shall keep the
_pslTXT record in place in the respective zone(s).Submitter affirms the following:
secops@tigrisdata.com
Abuse Contact:
Abuse contact information (email or web form) is available and easily accessible.
URL where abuse contact or abuse reporting form can be found:
abuse@tigrisdata.com
For PRIVATE section requests that are submitting entries for domains that match their organization website's primary domain, please understand that this can have impacts that may not match the desired outcome and take a long time to rollback, if at all.
To ensure that requested changes are entirely intentional, make sure that you read the affectation and propagation expectations, that you understand them, and confirm this understanding.
PR Rollbacks have lower priority, and the volunteers are unable to control when or if browsers or other parties using the PSL will refresh or update.
(Link: about propagation/expectations)
Description of Organization
Organization Website: https://www.tigrisdata.com/
Tigris Data, Inc. operates a globally distributed object storage platform compatible with the Amazon S3 API.
The service provides public bucket endpoints under dedicated subdomains that are assigned to independent customers.
This submission is made by an engineer responsible for the storage platform’s domain architecture and web security model.
Reason for PSL Inclusion
Tigris operates a multi-tenant object storage platform where each immediate subdomain under t3.storage.dev and t3.storageapi.dev (for example .t3.storage.dev) is assigned to a different customer.
Customers are mutually untrusted organizations and individuals and can serve arbitrary web-accessible content from these subdomains, including static websites and application assets.
Without a Public Suffix List entry at t3.storage.dev, browsers would compute the registrable domain as t3.storage.dev. This could allow one tenant to set cookies scoped to the parent domain and potentially interfere with other tenants’ applications hosted on sibling subdomains.
Adding these domains to the Public Suffix List ensures correct site boundary computation in browsers and aligns cookie security behavior with the platform’s ownership model.
Number of users this request is being made to serve:
~100,000 customers
DNS Verification