- From: Devdatta Akhawe <dev.akhawe@gmail.com>
- Date: Thu, 12 Dec 2013 15:34:02 -0800
- To: Mike West <mkwst@google.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>
- Cc: Dan Veditz <dveditz@mozilla.com>
Hi [creating a separate thread since there were other discussions ongoing in the other] > 2. 'unsafe-inline' is disabled if either a hash or nonce is present. > [3] https://dvcs.w3.org/hg/content-security-policy/rev/8db37e53da82 Imagine a website that wants to control what external scripts are loaded. The website uses inline event handlers too. The hosts for external scripts can be dynamic (e.g., it is on a CDN) and thus it uses nonces to load them at runtime. In the new design, all the event handlers would stop working. I am not sure this is what we want. Thanks Dev
Received on Thursday, 12 December 2013 23:34:49 UTC