W3C home > Mailing lists > Public > public-webappsec@w3.org > September 2014

Re: CSP reports on eval() and inline

From: Pete Freitag <pete@foundeo.com>
Date: Fri, 5 Sep 2014 10:28:27 -0400
Message-ID: <CAADZ8V5aT0JSo9ByJjNRoy-TcqsA7e2AN7Y+UWvton30VsAweA@mail.gmail.com>
To: "Hill, Brad" <bhill@paypal.com>
Cc: Neil Matatall <neilm@twitter.com>, Mike West <mkwst@google.com>, Pawel Krawczyk <pawel.krawczyk@hush.com>, "Daniel Veditz <dveditz@mozilla. com>" <dveditz@mozilla.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>
On Thu, Sep 4, 2014 at 2:11 PM, Hill, Brad <bhill@paypal.com> wrote:

> If one implementation is reporting something that users find sane and
> useful, where other implementations aren't reporting anything, documenting
> and converging on the existing useful behavior would be my strongest
> preference.
>

I find the "script-sample" that Firefox sends in CSP reports to be very
useful.

--
Pete Freitag
http://content-security-policy.com/ - CSP Quick Reference
Received on Friday, 5 September 2014 14:35:32 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:06 UTC