The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Newsgroups: mozilla.dev.security
From: Brandon Sterne <bste...@mozilla.com>
Date: Mon, 6 Apr 2009 16:52:28 -0700 (PDT)
Local: Mon, Apr 6 2009 7:52 pm
Subject: Re: Content Security Policy - final call for comments
Hi, Gerv. Thanks a lot for your comments. I'll address the comments
that weren't already covered by Johnathan or Sid, both of whom I agree with. On Apr 6, 3:56 am, Gervase Markham <g...@mozilla.org> wrote: > Are we expecting to see some or all of this in Firefox 3.5, or Firefox-next? Firefox-next. > - "but a declared (unexpanded) policy always has the "allow" directive." Sid did address this one, but I want to be clear in the rationale. > I think you need to make it more clear that "allow" is mandatory. But > what was the logic behind making it so? Why not assume "allow *", which > is what browsers do in the absence of CSP anyway? Once we see the Content Security Policy header (or meta tag), we want to force sites to be explicit about what they are allowing. Yes, "allow *" is the default browser behavior without CSP presently, but we want to avoid cases where sites assume the default behavior of CSP is more restrictive than it actually is. I could envision, for example, a site presuming that "allow none" or "allow self" was the default, and that additional policy could be specified from there. If a site really wants to "allow *", then we want them to explicitly state that. > And the other document That sounds fair. I'll update the document with that change. > http://people.mozilla.org/~bsterne/content-security-policy/details.html: > - "policy-uri documents must be served with the MIME type > - "Hostname, including an optional leading wildcard, e.g. *.mozilla.org" That's true too. I'll make the language more clear. > Does that include foo.bar.baz.mozilla.org? If so, we should say so > explicitly (in both docs). Cheers, You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||