Re: [spec-reviews] CSP (#42)

@mikewest - another CSP issue worth talking about again is the delivery mechanism. When I look at sites like Twitter, who have really long CSP headers:

... it makes me think we can do better (especially considering that this will consume most of the compression context in HTTP/2 -- 4k -- meaning it'll make header compression really inefficient). 

I've been noodling on a mechanism to allow a site to put its policies in a .well-known location and then refer to them by a token in responses when the client indicates it's fetched that location; would you care to look at a straw-spec?

Reply to this email directly or view it on GitHub:

Received on Friday, 25 September 2015 02:11:28 UTC