webappsec-ISSUE-42 (CSS Nonce): Script-nonce allows inline script, similar treatment for inline css?

webappsec-ISSUE-42 (CSS Nonce): Script-nonce allows inline script, similar treatment for inline css?

http://www.w3.org/2011/webappsec/track/issues/42

Raised by: Brad Hill
On product: 

http://lists.w3.org/Archives/Public/public-webappsec/2012Dec/0047.html

Inline CSS is considered essential for web performance by many.  Should we add a css-nonce directive similar to script-nonce, or a more generic inline-nonce facility?

Received on Friday, 1 February 2013 04:57:45 UTC