The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Newsgroups: mozilla.dev.security
From: Daniel Veditz <dved...@mozilla.com>
Date: Wed, 08 Jul 2009 10:05:11 -0700
Local: Wed, Jul 8 2009 1:05 pm
Subject: Re: Content Security Policy Spec questions and feedback
Sid Stamm wrote: I had always assumed that if we were going to report anything, it'd be > You raise some excellent questions... you know, I hadn't really thought > about what to do about reporting inline script violations. I think the > intention was to just *not run* the violating script, but reporting the > violation is definitely a good idea since much of XSS happens this way. an inline script attempt -- the heart of most XSS attacks. > How about this: the report either contains a I'm not keen on the either/or, can we pick one that will serve for both? > "violated-directive" field or "violated-base-restriction" field. There are not many policies that are not directives, we can define in the spec what we will send for those violations. e.g. I don't care so much what the tagname is (although Suggestions for the tag could be >> For clarification, if the entire policy was "allow self othersite.com" I prefer sending the actual policy, I just want the spec to be clear >> and we tried to load an image in violation of that policy, would the >> violated-directive be the implied img-src or the allow fall-back that is >> actually specified? I imagine it would be the allow directive. > There's arguments for both choices: > 1. We could send the "allow" directive for ease in figuring out which > directive was violated; this is the most straightforward report. about what happens. > Maybe we can compromise and say something like: I like either of your first suggestions over a wishy-washy sending both. > <violated-directive>(allow as img-src) self > othersite.com</violated-directive> > Thoughts? You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||