Re: [webappsec] CSP: are blob uri's really just origin='self'?

On Fri, Aug 30, 2013 at 10:26 PM, Ian Melven <ian.melven@gmail.com> wrote:
> according to http://www.w3.org/TR/FileAPI/#originOfBlob :
>
> The origin of a Blob URI must be the origin of the script that called
> URL.createObjectURL. Blob URIs must only be valid within this origin.

Please please please, never read TR! This requirement has been
removed: http://dev.w3.org/2006/webapi/FileAPI/


-- 
http://annevankesteren.nl/

Received on Tuesday, 3 September 2013 09:37:57 UTC