Re: [whatwg/webidl] Consider adding an `[InjectionMitigated]` extended attribute. (Issue #1440)

> @shhnjk: I think this is what the proposal in [w3c/webappsec-csp#665](https://github.com/w3c/webappsec-csp/pull/665) would address? If we landed that, we'd change the rules here accordingly.

Oh nice! Yup, that would work, though it just means that a `createScript` exists, but it is not validated (i.e. it could just be `createScript: s=>s`). But I don't have a good answer to what "validation" here means from a browser point of view, so I think this is a good start for V1 proposal.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/webidl/issues/1440#issuecomment-2400410665
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/webidl/issues/1440/2400410665@github.com>

Received on Tuesday, 8 October 2024 17:13:14 UTC