On Fri, Oct 9, 2015 at 3:45 AM, Mike West <mkwst@google.com> wrote:
> So, while rewriting most of CSP, I think I've decided that Brian was
> right, way back in
> https://lists.w3.org/Archives/Public/public-webappsec/2014Jun/0162.html.
> CSP is simpler to conceptualize as a purely restrictive mechanism, and
> I'm on board with the idea that we should keep it that way.
I noticed that the current editor's draft of CSP 3 [1] only mentions the
proposed reflected-xss directive in one place, and doesn't attempt to
define it. Ti be consistent with the idea above, it seems like
reflected-xss should also be removed from CSP3, which would currently
require just removing "reflected-xss, " from the editor's draft. Is that
what you're intending.
[1] https://w3c.github.io/webappsec-csp/
Cheers,
Brian
--
https://briansmith.org/