W3C home > Mailing lists > Public > public-webappsec@w3.org > January 2015

Re: Proposal: A pinning mechanism for CSP?

From: Jim Manico <jim.manico@owasp.org>
Date: Fri, 23 Jan 2015 09:26:51 -0800
Message-ID: <-2968452850242752597@unknownmsgid>
To: Anne van Kesteren <annevk@annevk.nl>
Cc: Frederik Braun <fbraun@mozilla.com>, Mike West <mkwst@google.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, yan zhu <yan@mit.edu>, Chris Palmer <palmer@google.com>, Ryan Sleevi <sleevi@google.com>, Brad Hill <hillbrad@gmail.com>, Dan Veditz <dveditz@mozilla.com>
> What is a page?

•grin• I meant per-response.

--
Jim Manico
@Manicode
(808) 652-3805

> On Jan 23, 2015, at 9:18 AM, Anne van Kesteren <annevk@annevk.nl> wrote:
>
>> On Fri, Jan 23, 2015 at 6:11 PM, Jim Manico <jim.manico@owasp.org> wrote:
>> We need to apply these headers differently per-page at times, so I say
>> no to a manifest-like structure.
>
> What is a page?
>
> None of these pinning solutions are more granular than a host.
>
>
> --
> https://annevankesteren.nl/
Received on Friday, 23 January 2015 17:27:19 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:09 UTC