W3C home > Mailing lists > Public > public-web-security@w3.org > August 2011

object-src and plugins with no URLs

From: Adam Barth <w3c@adambarth.com>
Date: Thu, 4 Aug 2011 17:29:11 -0700
Message-ID: <CAJE5ia-S5Jinah4HCsWAB4SGbGng7+_QXSTrMHXpWy+W8+6i1g@mail.gmail.com>
To: public-web-security@w3.org
How should object-src 'self' (for example) interact with the following
object tag?

<object type="application/x-plugin-that-does-not-make-any-http-requests"></object>

What about object-src * and object-src 'none'  ?

Adam
Received on Friday, 5 August 2011 00:30:09 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Friday, 5 August 2011 00:30:11 GMT