Contact emails [email protected]
Explainer No information provided Specification https://w3c.github.io/webappsec-cspee/#subsume-policy,https://github.com/w3c/webappsec-cspee/pull/36 Summary CSP Embedded Enforcement checks the `require-trusted-types-for` and `trusted-types` directives when determining whether an embedded document satisfies an iframe's required CSP. This allows embedding sites to require Trusted Types protections before an embedded document loads. Blink component Blink>SecurityFeature>ContentSecurityPolicy Web Feature ID csp Motivation CSP Embedded Enforcement lets an embedding page require an iframe response to enforce a specified Content Security Policy before it loads. Its subsumption check currently ignores the `require-trusted-types-for` and `trusted-types` directives, so embedders cannot use this mechanism to require Trusted Types protections. Supporting these directives allows embedding applications to verify that embedded content enforces the required Trusted Types restrictions before loading. Note: No separate explainer is planned because this change does not introduce new API surface. It closes a gap in the existing subsumption check that prevents embedders from requiring and verifying Trusted Types protections on iframe responses. Initial public proposal https://github.com/w3c/webappsec-csp/issues/628 Goals for experimentation None Requires code in //chrome? False Tracking bug https://issues.chromium.org/issues/40912894 Estimated milestones No milestones specified Link to entry on the Chrome Platform Status https://chromestatus.com/feature/5199775795380224?gate=5103628120621056 This intent message was generated by Chrome Platform Status. -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6aa02c31.e2ff090c.21b637.002e.GAE%40google.com.
