> Should this POST request be possibly restricted by CSP and if so which
> directive would apply ? I would
> propose "yes, CSP should apply, using connect-src" as a strawman. I know
> others may disagree, see
> for some examples
> :)

I'd talked with Mario about this at some point in the past, and suggested
`form-action` for both <a ping> and Beacon. I'd be fine with `connect-src`
as well.

Generally, I agree that both ought to be goverened by CSP. Beacon much
moreso than <a ping>.


