Re: CSP: set of report URIs

There is not a guarantee that the report URIs are same-origin, though I
believe Mozilla enforces that requirement (Daniel? Can you confirm?).

WebKit uses the same mechanism for these requests as used for hyperlink
auditing, which has similar requirements. Can you elaborate on the value of
adding a CORS preflight to the mix?


Mike West <>, Developer Advocate
Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany
Google+:, Twitter: @mikewest, Cell: +49 162 10 255 91

On Tue, Mar 19, 2013 at 12:16 PM, Anne van Kesteren <>wrote:

> Is this set of URLs guaranteed to be same-origin somehow? Doing a
> cross-origin POST request with a JSON entity body is not something
> either <form> or XMLHttpRequest with CORS can do so would require at
> least a CORS preflight.
> --

Received on Tuesday, 19 March 2013 14:55:20 UTC