CSP Plugin

Hello all,
 
I want to initiate some discussions about allow-plugin in sandbox.
 
There was some discussion in the mailing list before:
https://lists.w3.org/Archives/Public/public-web-security/2011Feb/0112.html
 
Can we add an allow-plugins policy that turns on plugins that understand the
HTML sandbox?
 
By default, the plugins can be blocked by the browser, but in the sandbox,
we can allow plugins. This can improve the web security.


Any feedback about this?


Thanks,
 
Kind Regards
 
Kepeng Li
Alibaba Group

Received on Thursday, 27 August 2015 13:26:49 UTC