W3C home > Mailing lists > Public > public-webappsec@w3.org > February 2015

Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)

From: Brian Smith <brian@briansmith.org>
Date: Thu, 5 Feb 2015 14:13:57 -0800
Message-ID: <CAFewVt72NCKZdmzWQ=XMitWOam3-AuantT4BZhCFKkhKnyzv3g@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
Cc: Mike West <mkwst@google.com>, Anne van Kesteren <annevk@annevk.nl>, WebAppSec WG <public-webappsec@w3.org>, "Oda, Terri" <terri.oda@intel.com>
I suggest that you drop IP addresses completely from the syntax for
CSP 2, and open an issue to address this in CSP 3. Implementations can
continue to accept the IP address form if they want, to gather data.
This would expedite the process of finishing CSP 2.

Cheers,
Brian
Received on Thursday, 5 February 2015 22:14:24 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:10 UTC