Newsgroups: mozilla.dev.security
From: Gervase Markham <g...@mozilla.org>
Date: Mon, 06 Apr 2009 11:56:00 +0100
Subject: Re: Content Security Policy - final call for comments
Hi Brandon,
Thanks for your continued hard work on this. Are we expecting to see some or all of this in Firefox 3.5, or Firefox-next? On 02/04/09 22:12, Brandon Sterne wrote: > If you have feedback that you would like to share regarding Content Here are some comments on https://wiki.mozilla.org/Security/CSP/Spec. In > Security Policy, please do so ASAP as the window for making changes to > the model will soon be closing. general, I think it's excellent :-) - When might we see the "Refinements" section with the JS/eval changes? - "When both a X-Content-Security-Policy HTTP header and meta tag are Surely you mean "strict", not "relaxed"? The example seems to show that - What happens if a Report-URI encounters a redirect? We should say - Would it not be more flexible, with negligible change in - "but a declared (unexpanded) policy always has the "allow" directive." - The formal syntax uses "<host-expr-list>" but it's undefined in that - Should there be a space or other separator in the middle of - The Violation Report Sample has: And the other document - "policy-uri documents must be served with the MIME type - "Hostname, including an optional leading wildcard, e.g. *.mozilla.org" Again, great work :-) Gerv You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||