Re: webappsec-ISSUE-51: How to handle externally defined <element> with <link rel=import>

On Thu, Apr 25, 2013 at 4:16 PM, Anne van Kesteren <annevk@annevk.nl> wrote:
> On Thu, Apr 25, 2013 at 10:49 PM, Web Application Security Working
> Group Issue Tracker <sysbot+tracker@w3.org> wrote:
>> Create a new directive, e.g. import-src for allowing custom elements to be imported from an external source?
>
> Last I checked this can do the same as script, so you probably want to
> restrict via the same mechanism.

Yeah, we'll probably need to restrict <link rel=import> with
script-src so that it's not an XSS vector for existing web sites that
use CSP.

Adam

Received on Saturday, 27 April 2013 14:16:08 UTC