The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Newsgroups: mozilla.dev.security
From: Brandon Sterne <bste...@mozilla.com>
Date: Tue, 07 Apr 2009 09:22:19 -0700
Local: Tues, Apr 7 2009 12:22 pm
Subject: Re: Content Security Policy - final call for comments
On 4/6/09 11:36 PM, Daniel Veditz wrote:
> "allow" is not mandatory, but if missing it's assumed to be "allow Not according to our proposed spec: > none". If you explicitly specify the whitelisted hosts for each type of > load you might not need or want a global fallback which could only be > used to sneak through types you hadn't thought about. Future browser > features, for instance. https://wiki.mozilla.org/Security/CSP/Spec#Directives http://people.mozilla.org/~bsterne/content-security-policy/details.ht... See comments from me and Sid from yesterday explaining why allow is I somewhat agree with the spirit of Dan's comment. If allow is not By falling back to "allow none" when invalid policy is sent, websites -Brandon You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||