W3C home > Mailing lists > Public > public-webappsec@w3.org > June 2014

Re: CSP wildcard host matching

From: Anne van Kesteren <annevk@annevk.nl>
Date: Sun, 29 Jun 2014 11:32:42 +0200
Message-ID: <CADnb78gPYB96jiMnZ_QVRVH1P_UqMe4dpeU6bb1hY_Qj7Yzfow@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Sid Stamm <sid@mozilla.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>
On Sun, Jun 29, 2014 at 10:49 AM, Mike West <mkwst@google.com> wrote:
> Any objections from the WG to changing the spec to allow `*.example.com` to
> mean `example.com` plus any and all subdomains?

That seems rather magical. Normally those would be distinct origins.


-- 
http://annevankesteren.nl/
Received on Sunday, 29 June 2014 09:33:09 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:05 UTC