Newsgroups: mozilla.dev.security
From: Gervase Markham <g...@mozilla.org>
Date: Wed, 08 Jul 2009 17:25:26 +0100
Local: Wed, Jul 8 2009 12:25 pm
Subject: Re: Content Security Policy Spec questions and feedback
On 07/07/09 19:18, Sid Stamm wrote:
> I personally want to eradicate the META tag My comment: > (http://blog.sidstamm.com/2009/06/csp-with-or-without-meta.html). This > should be discussed more in depth to decide if we should remove META > support, if we should support multiple HTTP headers, etc. Why not allow multiple headers, and keep the intersection algorithm? This way, the hosting company has to provide a special interface for This means you still need the policy intersection logic, so that part of However, I would now add that removing <meta> support (i.e. inline > Spec updated to support relative URIs. I don't think CSP should interact I agree. Even with <meta>, it's just saying "hey, here's a header you > with the BASE tag at all. didn't get". So none of your <base> are belong to us. >> What happens to CSP if I save a CSP-protected document to my local Let's say content saved to disk should just lose its CSP. What would be >> disk? I’d assume it would be ignored (because many restrictions could >> be broken) but this should be explicit. Also, when saving docs to >> disk, HTTP headers are lost, so to preserve it, you’d need to >> explicitly serialize to a META tag, which could get complicated if the >> document already had a CSP META… > Under discussion. the disadvantages of that policy? > Updated spec to allow "https://self:443" syntax. Self flexible and may Good idea. > or may not include scheme and port. When absent from the expression, > scheme or port are inherited. >> Apparently, ASP.NET controls are tightly bound to use of JavaScript: I think we need to figure out whether permitting this in fact blows all >> protocol URIs, and this isn’t likely to be easily changed. For that >> reason, it might be interesting to have a way to allow only those URIs >> and not inline script blocks, event handlers, etc? > Under Discussion. protection out of the water, or not. Gerv You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||