Newsgroups: mozilla.dev.security
From: Brandon Sterne <bste...@mozilla.com>
Date: Tue, 07 Apr 2009 10:02:12 -0700
Local: Tues, Apr 7 2009 1:02 pm
Subject: Re: Content Security Policy - final call for comments
On 4/7/09 4:07 AM, Gervase Markham wrote:
> I much prefer forwardly-compatible designs to version numbers. I think I think the case for including a version number goes something like this > the current design is forwardly-compatible, as long as we maintain a > well-signposted public page listing which category all sorts of request > fall into, and add new request types well before they get implemented by > anyone. > For example, if a <3dvideo> tag, for which you needed red-blue glasses, > Can you suggest a scenario in which version numbers would help? (and strong advocates, please chime in if I miss something): 1. Bugs may be present in the CSP design which require future 2. New types of content (per your example) or new web APIs may be added 3. We arguably want to have a pref for users to turn off CSP (for I looked at each of the HTTP Header Field Definitions and my preference Thoughts? -Brandon [1] http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.8 You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||