Re: FW: Java Script Client

David Bruant <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
Le 27/05/2014 19:05, Stiegler, Marc a écrit :
>
> As nearly as I can tell, the main goal of the Content Security Policy 
> meta tag
>
CSP is preferably used as an HTTP header. The meta tag is a recent 
addition and only a fallback for contexts where you cannot set HTTP 
headers (things like shared hosting, github pages, etc.)

> is to prevent XSS. But they carefully, and correctly, assert that it 
> does not actually fully prevent XSS. And the caveats  about what it 
> does and does not prevent are so complicated that the only safe policy 
> is to conduct rigorous XSS hygiene on the content you display anyway. 
> I.e., you should turn it on, but then you must assume that it does not 
> work.
>
How so? Which caveat are you referring to?

David

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.