W3C home > Mailing lists > Public > public-webappsec@w3.org > April 2014

Worker / SharedWorker directive

From: Mike West <mkwst@google.com>
Date: Fri, 25 Apr 2014 08:25:07 +0000
Message-ID: <CAKXHy=e8v+ho+ohxJ-TTqdvYn+a4BK-pB9dfsvW-ZZZef4Xnow@mail.gmail.com>
To: Anne van Kesteren <annevk@annevk.nl>, WebAppSec WG <public-webappsec@w3.org>
My fault: removed Worker/SharedWorker from 'script-src' in
https://github.com/w3c/webappsec/commit/ad525f13d111ba366b4fae9678b6097e5ee829ad
.

Note that 'importScripts' should still be controlled by the 'script-src'
directive of whatever policy the Worker is running with.

-mike

On Thu Apr 24 2014 at 5:11:05 PM, Anne van Kesteren <annevk@annevk.nl>
wrote:

> Is it child-src or script-src? Specification lists them under both.
>
>
> --
> http://annevankesteren.nl/
>
>
Received on Friday, 25 April 2014 08:25:36 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:05 UTC