Re: Way of CSP code in FF

2013-03-18 Thread Ian Melven
laces that for allowing inline script is checked, for example. cheers, ian - Original Message - From: "jeremy ralegh" To: dev-security@lists.mozilla.org Sent: Saturday, March 16, 2013 5:53:26 AM Subject: Way of CSP code in FF Hello, after reading through many lines of code to

Way of CSP code in FF

2013-03-16 Thread jeremy . ralegh
Hello, after reading through many lines of code to understand CSP implementation in FF I'm still a bit confused. How exactly is the code flow when one opens a web site in FF that uses a CSP policy? I mean, I've checked files like contentSecurityPolicy.js, CSPUtils.jsm, nsIContentPolicy.h and s