Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)

On Thu, Jan 29, 2015 at 10:46 AM, Mike West <mkwst@google.com> wrote:
> For me, the question is whether the window has already closed in which we
> could have created such a restriction. Given that we've been shipping with
> IPv4 support for ~2 years, it wouldn't surprise me if applications had come
> to depend in one way or another on the behavior.

Given that nothing else outlaws public IP addresses we probably want
to support them in the long term. The main problem is the parsing and
comparison not being defined in sufficient detail.


-- 
https://annevankesteren.nl/

Received on Thursday, 29 January 2015 09:54:56 UTC