Re: [fossil-dev] Content-Security-Policy Was: Fossil README symlink

2017-11-03 Thread Ben Summers
> On 30 Oct 2017, at 12:52, Richard Hipp wrote: > > On 10/18/17, Richard Hipp wrote: >> On 10/18/17, Warren Young wrote: >>> On Oct 18, 2017, at 3:44 AM, Warren Young wrote: The more web apps that ship with stringent Content-Security-Policy headers, the fewer arguments we’ll h

Re: [fossil-dev] Content-Security-Policy Was: Fossil README symlink

2017-10-30 Thread Richard Hipp
On 10/18/17, Richard Hipp wrote: > On 10/18/17, Warren Young wrote: >> On Oct 18, 2017, at 3:44 AM, Warren Young wrote: >>> >>> The more web apps that ship with stringent Content-Security-Policy >>> headers, the fewer arguments we’ll have for allowing JS on web pages. > > I'd never heard of Cont