- From: Viktoria Zlatinova <notifications@github.com>
- Date: Mon, 31 Aug 2026 09:32:51 -0700
- To: whatwg/fetch <fetch@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
- Message-ID: <whatwg/fetch/pull/1841/review/5068821739@github.com>
@vickiez commented on this pull request. > <td>"<code>report</code>" - <td rowspan=2>— + <td rowspan=3>— Hi all, I’d like to reopen this discussion as we’re working to support external speculation rules to make them easier for developers to deploy (https://github.com/whatwg/html/pull/11697 and https://github.com/w3c/webappsec-csp/pull/808). In [CSP #808](https://github.com/w3c/webappsec-csp/pull/808), we propose introducing `speculation-rules-src` to control inline and external speculation rule sets. This again raises the question of whether the directive should also apply to rule sets fetched through the `Speculation-Rules` header. https://github.com/w3c/webappsec-csp/pull/808#issuecomment-5398653996 highlights that a major use case for the header is platforms and CDNs such as Shopify and Cloudflare automatically enabling speculation for many customers. Requiring those customers to add `speculation-rules-src` could introduce compat risk and deployment friction, potentially reducing the benefit. Is anyone here in contact with the affected platforms or customers so we can better understand the impact? Also, can we land the `speculationrules` destination change separately here to unblock the HTML change while we discuss the appropriate CSP behavior for header fetches? -- Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/pull/1841#discussion_r3896383613 You are receiving this because you are subscribed to this thread. Message ID: <whatwg/fetch/pull/1841/review/5068821739@github.com>
Received on Monday, 31 August 2026 16:32:55 UTC