The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Newsgroups: mozilla.dev.security
From: Daniel Veditz <dved...@mozilla.com>
Date: Tue, 07 Jul 2009 16:59:45 -0700
Local: Tues, Jul 7 2009 7:59 pm
Subject: Re: Content Security Policy Spec questions and feedback
Sid Stamm wrote: Just jumping off here on a related topic: What do we send as the >> Also, the “blocked-headers” is defined as required, but not all >> schemes (specifically, FTP and FILE) do not use headers. > Removed the requirement to send "request-headers" from the XML schema > (implied optional). "blocked-uri" when we find inline script? Since this is perhaps the most common injection type this would be a good one for an example. I suppose we could leave blocked-uri empty and let people infer that it For clarification, if the entire policy was "allow self othersite.com" You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||