W3C home > Mailing lists > Public > public-webappsec@w3.org > May 2013

Re: CSP: workers

From: Anne van Kesteren <annevk@annevk.nl>
Date: Sat, 11 May 2013 07:14:41 -0700
Message-ID: <CADnb78goGsv_ukFLJzcQwZsL7NopHdBTVhM8OEhDKkuwN4Zg_A@mail.gmail.com>
To: WebAppSec WG <public-webappsec@w3.org>
On Fri, May 10, 2013 at 1:18 PM, Anne van Kesteren <annevk@annevk.nl> wrote:
> What happens with multiple documents with distinct CSP headers that
> use a shared worker?

So someone told me that the idea of workers was more or less to be
background documents. From that perspective CSP should apply to them
directly really (and for the controller idea they would be treated
similarly to a browsing context navigation), though I guess you still
want to do the same things you do with <iframe> where sometimes you
inherit the policy (e.g. for data URLs).

Received on Saturday, 11 May 2013 14:15:10 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:33 UTC