Earlier quoted context omitted.
A website where a user can upload "active code". The definition of "active code" is broad & sometimes debatable - e.g. do old MySpace websites count - but broadly speaking the best way of thinking about it is in terms of threat model, & the main two there are: - credential leakage - phishing The first is fairly narrow & pertains to uploading server side code or client javascript. If Alice hosts a login page on alice.…
It may be dangerous but it is an established pattern. There are many cases (like Cloudflare Pages) of others doing the same, hosting strangers' sites on subdomains of a dedicated domain (pages.dev for Cloudflare, immich.cloud for Immich). By preventing newcomers from using this pattern, Google's system is flawed, severely stifling competition. Of course, this is perfectly fine for Google.
1. Use a separate dedicated domain (Immich didn't do this - they're now switching to one in response to this)
2. List the separate dedicated domain in the public suffix list. As far as I can tell Immich haven't mentioned this.