Re: Strict mixed content checking (was Re: MIX: Exiting last call?)

>> Yes, like that, but which cascades to descendant contexts.

It does cascade; it sets the document's flag, and nested browsing contexts
read that flag when they're created (or, that's what I intended
to express :)).

> I guess that would be implied by the iframe sandbox attribute which would
> be included-by-reference into CSP's sandbox directive.  It just seems ugly
> that you'd have to set a sandbox and christmas-tree the flags to get this
> behavior.  It also seems a bit out-of-pattern to add new flags to
> sandboxing in this way.  All the other flags loosen the sandbox.

I don't understand your point here. :/

> (this was probably a poor design choice from a forward evolution
> standpoint, now that I think about it, but that ship has sailed)

That was a poor design choice for future work, as it makes it virtually
impossible to add new sandbox flags. :/


