Account Options

  1. Sign in
The old Google Groups will be going away soon.
Switch to the new Google Groups.
Google Groups Home
« Groups Home
Message from discussion Content Security Policy - final call for comments
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Brandon Sterne  
View profile  
 More options Apr 6 2009, 7:52 pm
Newsgroups: mozilla.dev.security
From: Brandon Sterne <bste...@mozilla.com>
Date: Mon, 6 Apr 2009 16:52:28 -0700 (PDT)
Local: Mon, Apr 6 2009 7:52 pm
Subject: Re: Content Security Policy - final call for comments
Hi, Gerv.  Thanks a lot for your comments.  I'll address the comments
that weren't already covered by Johnathan or Sid, both of whom I agree
with.

On Apr 6, 3:56 am, Gervase Markham <g...@mozilla.org> wrote:

> Are we expecting to see some or all of this in Firefox 3.5, or Firefox-next?

Firefox-next.

> - "but a declared (unexpanded) policy always has the "allow" directive."
> I think you need to make it more clear that "allow" is mandatory. But
> what was the logic behind making it so? Why not assume "allow *", which
> is what browsers do in the absence of CSP anyway?

Sid did address this one, but I want to be clear in the rationale.
Once we see the Content Security Policy header (or meta tag), we want
to force sites to be explicit about what they are allowing.  Yes,
"allow *" is the default browser behavior without CSP presently, but
we want to avoid cases where sites assume the default behavior of CSP
is more restrictive than it actually is.  I could envision, for
example, a site presuming that "allow none" or "allow self" was the
default, and that additional policy could be specified from there.  If
a site really wants to "allow *", then we want them to explicitly
state that.

> And the other document
> http://people.mozilla.org/~bsterne/content-security-policy/details.html:

> - "policy-uri documents must be served with the MIME type
> text/content-security-policy to be valid" This probably needs an "x-"
> until we've registered it, which we should do before deployment. It's
> not a complex process, I hear.

That sounds fair.  I'll update the document with that change.

> - "Hostname, including an optional leading wildcard, e.g. *.mozilla.org"
> Does that include foo.bar.baz.mozilla.org? If so, we should say so
> explicitly (in both docs).

That's true too.  I'll make the language more clear.

Cheers,
Brandon


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.