Re: CfC to publish a LCWD of CSP 1.1

On Wed, Jun 11, 2014 at 10:14 AM, Mike West <mkwst@google.com> wrote:
> * Redirects are blocked by default: authors must opt-in to enabling
> redirects (which must still match directives' source list) via the new
> 'unsafe-redirect' source expression:
> https://github.com/w3c/webappsec/commit/d1fd42a6df58ef2a7afedcd12ae2bff76a096d1a

How does this prevent the direct from happening? It seems to only talk
about the final URL?

Also, why are we still using the term URI in the specification? I feel
a bit like a broken record at this point, but CSP is the only
specifications that does this within web platform land.

It also still talks about 400 response. I raised the point about it
having to be a network error ages ago. What's the hold up?

Fetch integration will be done in CSP 1.2? I was sort of hoping
sooner, but I guess that is okay.


-- 
http://annevankesteren.nl/

Received on Wednesday, 11 June 2014 09:32:17 UTC