- From: Notifier <notifier@aries.w3.org>
- Date: Tue, 21 Jul 2015 16:00:50 +0000
- To: public-review-announce@w3.org
- Message-Id: <E1ZHZyM-0007Qd-Sd@aries.w3.org>
Content Security Policy Level 2 http://www.w3.org/TR/2015/CR-CSP2-20150721/ feedback due by: 2015-08-21 Abstract This document defines a policy language used to declare a set of content restrictions for a web resource, and a mechanism for transmitting the policy from a server to a client where the policy is enforced. Status of the Document This section describes the status of this document at the time of its publication. Other documents may supersede this document. A list of current W3C publications and the latest revision of this technical report can be found in the W3C technical reports index at http://www.w3.org/TR/. This document was published by the Web Application Security Working Group as a Candidate Recommendation. This document is intended to become a W3C Recommendation. This document will remain a Candidate Recommendation at least until 21 August 2015 in order to ensure the opportunity for wide review. The (archived) public mailing list public-webappsec@w3.org (see instructions) is preferred for discussion of this specification. When sending e-mail, please put the text “CSP2” in the subject, preferably like this: “[CSP2] …summary of comment…” Publication as a Candidate Recommendation does not imply endorsement by the W3C Membership. This is a draft document and may be updated, replaced or obsoleted by other documents at any time. It is inappropriate to cite this document as other than work in progress. The entrance criteria for this document to enter the Proposed Recommendation stage is to have a minimum of two independent and interoperable user agents that implementation all the features of this specification, which will be determined by passing the user agent tests defined in the test suite developed by the Working Group. The Working Group will prepare an implementation report to track progress. This document was produced by a group operating under the 5 February 2004 W3C Patent Policy. W3C maintains a public list of any patent disclosures made in connection with the deliverables of the group; that page also includes instructions for disclosing a patent. An individual who has actual knowledge of a patent which the individual believes contains Essential Claim(s) must disclose the information in accordance with section 6 of the W3C Patent Policy. This document is governed by the 1 August 2014 W3C Process Document. The following features are at-risk, and may be dropped during the CR period:§3.4 The CSP HTTP Request Header §7.2 child-src
Received on Tuesday, 21 July 2015 16:00:52 UTC