Re: Behavior when default-src is missing from a CSP

On Thu, Oct 10, 2013 at 1:25 AM, Neil Matatall <neilm@twitter.com> wrote:

> Ian pointed out that this only happens with the X- header on Firefox.
> However, it still appears to be undefined in the spec.
>

Not anymore: https://dvcs.w3.org/hg/content-security-policy/rev/b7108185b416:)

-mike

Received on Thursday, 10 October 2013 11:56:58 UTC