Re: Content Security Policy updates

2009-07-23 Thread Sid Stamm
On 7/23/09 11:25 AM, Bil Corry wrote: > Sid Stamm wrote on 7/23/2009 11:41 AM: >> On 7/23/09 9:36 AM, Bil Corry wrote: >>> And that section conflicts with what is said earlier in the document, >>> specifically: >>> "When multiple instances of the X-Content-SecurityPolicy HTTP header are >>> pres

Re: Content Security Policy updates

2009-07-23 Thread Bil Corry
Sid Stamm wrote on 7/23/2009 11:41 AM: > On 7/23/09 9:36 AM, Bil Corry wrote: >> And that section conflicts with what is said earlier in the document, >> specifically: >> "When multiple instances of the X-Content-SecurityPolicy HTTP header are >> present in an HTTP response, the intersection of

Re: Content Security Policy updates

2009-07-23 Thread Sid Stamm
On 7/23/09 9:36 AM, Bil Corry wrote: > Under "Policy Refinements with a Multiply-Specified Header" there is a > misspelling of "X-Content-SecurityPolicy". Fixed. > And that section conflicts with what is said earlier in the document, > specifically: > "When multiple instances of the X-Content-Se

Re: Content Security Policy updates

2009-07-23 Thread Bil Corry
Daniel Veditz wrote on 7/23/2009 10:32 AM: > Sid has updated the Content Security Policy spec to address some of the > issues discussed here. https://wiki.mozilla.org/Security/CSP/Spec Under "Policy Refinements with a Multiply-Specified Header" there is a misspelling of "X-Content-SecurityPolicy

Content Security Policy updates

2009-07-23 Thread Daniel Veditz
Sid has updated the Content Security Policy spec to address some of the issues discussed here. https://wiki.mozilla.org/Security/CSP/Spec You can see the issues we've been tracking and the resolutions at the Talk page: https://wiki.mozilla.org/Talk:Security/CSP/Spec There are still a few open iss