Re: CSP 1.1: `script-nonce` and script interface edits.

Hi Mike:


> * `script-nonce` has been cleaned up a bit, adding a non-normative "Usage"
> section that attempts to explain the core functionality to web developers,
> and making two things clear that confused me while experimenting with a
> WebKit implementation. First, invalid nonces now fail loudly, blocking all
> script execution on a page.
>
Is there a particular motivation for this? (i.e., is there an attack that
would break the soft-fail case?)


-- 
-Eric

Received on Thursday, 19 July 2012 03:57:28 UTC