On Fri, Jan 23, 2015 at 6:11 PM, Jim Manico <jim.manico@owasp.org> wrote:
> We need to apply these headers differently per-page at times, so I say
> no to a manifest-like structure.
>
I think Freddy's proposal was related to the host-wide pinned items, not
the per-page CSP header.
Those pins could certainly fit into a manifest. Maybe that's even a good
idea!
The reason we've traditionally resisted going that route is that it would
involve either reducing the security of the initial request, or causing a
synchronous request to block loading a page. Neither seems like an awesome
tradeoff.
--
Mike West <mkwst@google.com>, @mikewest
Google Germany GmbH, Dienerstrasse 12, 80331 München,
Germany, Registergericht und -nummer: Hamburg, HRB 86891, Sitz der
Gesellschaft: Hamburg, Geschäftsführer: Graham Law, Christine Elizabeth
Flores
(Sorry; I'm legally required to add this exciting detail to emails. Bleh.)