W3C home > Mailing lists > Public > public-web-security@w3.org > April 2011

Re: style-src and inline style

From: Bil Corry <bil@corry.biz>
Date: Thu, 07 Apr 2011 00:00:08 -0700
Message-ID: <4D9D60F8.1060204@corry.biz>
To: Collin Jackson <collin.jackson@sv.cmu.edu>
CC: Brandon Sterne <bsterne@mozilla.com>, gaz Heyes <gazheyes@gmail.com>, Adam Barth <w3c@adambarth.com>, Daniel Veditz <dveditz@mozilla.com>, public-web-security@w3.org
Collin Jackson wrote on 4/6/2011 12:33 PM:
> Blocking inline styles for people who do use style-src seems both consistent and desirable.

One use case to consider: I want to allow only HTTPS stylesheets, and allow inline styles specifically for framebusting:

	https://www.codemagi.com/blog/post/194



- Bil
Received on Thursday, 7 April 2011 07:00:48 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Thursday, 7 April 2011 07:00:49 GMT