Re: XSS mitigation in browsers

On 1/19/11 3:12 PM, Michal Zalewski wrote:
> 3) Due to the prevalence of open redirectors, the policy should
> preferably apply not only to the initial URL, but also to every 30x
> hop encountered.

CSP enforces its policies on the entire redirect chain.

-Dan Veditz

Received on Saturday, 22 January 2011 03:56:49 UTC