Contact emails
[email protected]

Explainer
No information provided


Specification
https://w3c.github.io/webappsec-cspee/#subsume-policy,https://github.com/w3c/webappsec-cspee/pull/36


Summary
CSP Embedded Enforcement checks the `require-trusted-types-for` and 
`trusted-types` directives when determining whether an embedded document 
satisfies an iframe's required CSP. This allows embedding sites to require 
Trusted Types protections before an embedded document loads.


Blink component
Blink>SecurityFeature>ContentSecurityPolicy


Web Feature ID
csp


Motivation
CSP Embedded Enforcement lets an embedding page require an iframe response to 
enforce a specified Content Security Policy before it loads. Its subsumption 
check currently ignores the `require-trusted-types-for` and `trusted-types` 
directives, so embedders cannot use this mechanism to require Trusted Types 
protections. Supporting these directives allows embedding applications to 
verify that embedded content enforces the required Trusted Types restrictions 
before loading. Note: No separate explainer is planned because this change does 
not introduce new API surface. It closes a gap in the existing subsumption 
check that prevents embedders from requiring and verifying Trusted Types 
protections on iframe responses.


Initial public proposal
https://github.com/w3c/webappsec-csp/issues/628


Goals for experimentation
None


Requires code in //chrome?
False


Tracking bug
https://issues.chromium.org/issues/40912894


Estimated milestones

No milestones specified



Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/5199775795380224?gate=5103628120621056


This intent message was generated by Chrome Platform Status.

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6aa02c31.e2ff090c.21b637.002e.GAE%40google.com.

Reply via email to