- From: Mike West <mkwst@google.com>
- Date: Fri, 28 Aug 2015 07:09:35 +0200
- To: Brad Hill <hillbrad@gmail.com>
- Cc: timeless <timeless@gmail.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>
- Message-ID: <CAKXHy=c9DAyJjbg=D4c4yVz2o1dZRhYCw0VLu0Rx0-Nbp9u=WA@mail.gmail.com>
Thanks, Brad! And thanks for the careful review, timeless! On Fri, Aug 28, 2015 at 3:07 AM, Brad Hill <hillbrad@gmail.com> wrote: > PR addressing much of this at: > > https://github.com/w3c/webappsec/pull/462 > > Unaddressed issues from the review: > > * Fancy quotes. I live in fear of the question box for fancy quotes, so > not going to touch this one. > This looks like a Bikeshed bug more than anything else. My impression is that support for entity-encoded smart quotes is solid cross-browser. I'll look into it next week when I'm back at the office. > * Pluggable matching algorithm for unique identifier schemes > I think this ought to be using the "local scheme" definition from URL ( https://url.spec.whatwg.org/#local-scheme). I don't think making it pluggable is the right way to go, and browser-internal schemes are somewhat outside the scope of this document. That said, Chrome explicitly whitelists `chrome-extension:` URLs; they bypass CSP entirely. I'd love to recommend that other vendors do the same, but that seems to lead back into the exciting land of formal objections from Cox that we resolved a long time ago. I'm going to reopen that can of worms in CSP3 (sorry in advance, Brad!), but I think it's done for CSP2. * Java mime-type matching (please, can the Java plugin just die already?) > We just dropped support for `<applet>` in Chrome; I guess I'm disinclined to add `x-java-vm` and `x-java-bean` unless there's a real need. I suspect there isn't. -mike -- Mike West <mkwst@google.com>, @mikewest Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany, Registergericht und -nummer: Hamburg, HRB 86891, Sitz der Gesellschaft: Hamburg, Geschäftsführer: Graham Law, Christine Elizabeth Flores (Sorry; I'm legally required to add this exciting detail to emails. Bleh.)
Received on Friday, 28 August 2015 05:10:24 UTC