FYI, I've asked the webappsec group to consider extending their connect-src directive to allow sites to control whether WebRTC data channels are permitted. The connect-src directive covers websockets and HTTP fetch, so this seemed logical, though WebRTC won't allow a fine-grained, origin-based control. http://lists.w3.org/Archives/Public/public-webappsec/2014Aug/0162.htmlReceived on Friday, 29 August 2014 18:07:51 UTC
This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 19:18:00 UTC