W3C home > Mailing lists > Public > public-webappsec@w3.org > June 2013

Re: Fetching contexts

From: Boris Zbarsky <bzbarsky@MIT.EDU>
Date: Thu, 20 Jun 2013 10:17:54 -0400
Message-ID: <51C30F12.3030101@mit.edu>
To: Anne van Kesteren <annevk@annevk.nl>
CC: Gordon Hemsley <me@gphemsley.org>, Adam Barth <w3c@adambarth.com>, WebAppSec WG <public-webappsec@w3.org>
On 6/20/13 3:27 AM, Anne van Kesteren wrote:
> It seems XMLHttpRequest is connect-src.

OK.

> Workers are covered by script-src.

Is that actually specified somewhere?

> HTML component imports are covered by script-src (for
> now).

Likewise.

-Boris
Received on Thursday, 20 June 2013 14:18:32 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:02 UTC