- From: Yoav Weiss <yoav@yoav.ws>
- Date: Fri, 15 Nov 2013 17:27:07 +0000
- To: Adam Barth <w3c@adambarth.com>
- Cc: Markus Ernst <derernst@gmx.ch>, "Tab Atkins Jr." <jackalmage@gmail.com>, Ryosuke Niwa <rniwa@apple.com>, whatwg <whatwg@lists.whatwg.org>, "Jukka K. Korpela" <jkorpela@cs.tut.fi>, Markus Lanthaler <markus.lanthaler@gmx.net>
> > > > Any thoughts on my concerns with making inline CSS mandatory (especially > > from the CSP angle)? > > CSP 1.1 supports securing inline style and script with nonces and/or > hashes. > > OK, since the latest proposals keep the URLs outside the style, modifying the content image can keep the same style, assuming layout is identical. So these inline-style are not more likely to change than any other inline-styles and the authoring complexity is identical to other inline styles. Still - I'm not sure such a solution is author friendly.
Received on Friday, 15 November 2013 17:27:30 UTC