Newsgroups: mozilla.dev.security
From: Brandon Sterne <bste...@mozilla.com>
Date: Tue, 07 Apr 2009 12:27:16 -0700
Local: Tues, Apr 7 2009 3:27 pm
Subject: Re: Content Security Policy - final call for comments
On 4/7/09 9:08 AM, Brandon Sterne wrote:
>> Have we decided that there's a risk with all inline CSS style, or can we Actually, my reasoning is wrong here. >> define and enforce a large safe subset of the language? Making people >> move their JS to external files is one thing, making them move all the >> style as well is yet another. > Since style is a vector for JavaScript, via XBL, it needs to be subject Style is no longer a vector for script under CSP because we added the The other reason to make inline CSS subject to the style-src directive I don't think the no-inline-style requirement is too punitive, though, Sorry for the confusion. -Brandon You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||