Re: FW: Java Script Client
David Bruant <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
Le 27/05/2014 19:05, Stiegler, Marc a écrit : > > As nearly as I can tell, the main goal of the Content Security Policy > meta tag > CSP is preferably used as an HTTP header. The meta tag is a recent addition and only a fallback for contexts where you cannot set HTTP headers (things like shared hosting, github pages, etc.) > is to prevent XSS. But they carefully, and correctly, assert that it > does not actually fully prevent XSS. And the caveats about what it > does and does not prevent are so complicated that the only safe policy > is to conduct rigorous XSS hygiene on the content you display anyway. > I.e., you should turn it on, but then you must assume that it does not > work. > How so? Which caveat are you referring to? David _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk