Geolocation API
navigator.geolocation, getCurrentPosition, watchPositionDefinition
The browser API — navigator.geolocation.getCurrentPosition(success, error, options) — that asks the user’s permission and returns their position (latitude, longitude, accuracy, and a timestamp), from GPS, Wi-Fi or the network, with watchPosition for updates and options for accuracy and age
The API behind this site’s ZIP locator: one call, a permission prompt, a position, then a reverse lookup to a postal code — which is the proof page zip-from-geolocation walks through, including the parts the API leaves to you: the denied case, the timeout, the position that is a city-wide guess. Requires a secure context (HTTPS, or localhost), which is one of the reasons HTTPS was the first deliverable. The permission is the design: ask at the moment the position is needed and say why, never on load.
The browser will tell you where the reader is, once, if you ask well. Most of the work is what to do when it says no.