On 14 February 2016 at 16:39, Devdatta Akhawe <dev.akhawe@gmail.com> wrote:
Personally, my preference for increasing complexity is in the order---web apps and then browsers and then standards.
The priority of constituencies would (perfectly) disagree on this point.
https://www.w3.org/TR/html-design-principles/#priority-of-constituencies
The thing I'm trying to wrap my head around is how this fits with the general CSP design pattern. How does adding this directive narrow the set of things that are permitted? It actually appears to do the opposite. The purpose being to give dynamically inserted scripts an exemption.