Re: Adding cookie scope to CSP

On Fri, Sep 13, 2013 at 4:47 PM, Nottingham, Mark <mnotting@akamai.com> wrote:
> I don't see how CSP is competitive to those more ambitious approaches.

They would (hopefully!) solve the problem your CSP proposal is trying
to solve, but solve it in a broader way so cookies are protected
whether they are read/written via Javascript *or* HTTP headers.


Trevor

Received on Friday, 13 September 2013 23:57:40 UTC