W3C home > Mailing lists > Public > public-webappsec@w3.org > January 2014

Re: Beacon and CSP

From: Mike West <mkwst@google.com>
Date: Thu, 16 Jan 2014 09:57:42 +0100
Message-ID: <CAKXHy=eUqd=H8i=TOekNCq+7XkbUh5D7kvXQdvj7yzsuW4pb0w@mail.gmail.com>
To: Ian Melven <ian.melven@gmail.com>
Cc: "public-webappsec@w3.org" <public-webappsec@w3.org>
On Wed, Jan 15, 2014 at 7:16 PM, Ian Melven <ian.melven@gmail.com> wrote:

> Should this POST request be possibly restricted by CSP and if so which
> directive would apply ? I would
> propose "yes, CSP should apply, using connect-src" as a strawman. I know
> others may disagree, see
> https://bugzilla.mozilla.org/show_bug.cgi?id=936340#c17 for some examples
> :)
>

I'd talked with Mario about this at some point in the past, and suggested
`form-action` for both <a ping> and Beacon. I'd be fine with `connect-src`
as well.

Generally, I agree that both ought to be goverened by CSP. Beacon much
moreso than <a ping>.

-mike
Received on Thursday, 16 January 2014 08:58:31 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:04 UTC