Re: XSS mitigation in browsers

> "User Agents MUST NOT block:
> " * Scripts imported from external files whose sources are allowed by
> the protected document's policy AND are served with a Content-Type of
> application/javascript or application/json. "

Well, that's "MUST NOT block", not "MUST block the opposite" :-) But
yeah, that aspect is easy to fix.

/mz

Received on Thursday, 20 January 2011 23:03:33 UTC