Security/CSP/Spec: Difference between revisions

m
Line 115: Line 115:
** policy-uri directives which refer to a URI on a different host as the protected document, e.g. policy-uri http://other.tld/csp-policy.cgi
** policy-uri directives which refer to a URI on a different host as the protected document, e.g. policy-uri http://other.tld/csp-policy.cgi
** policy-uri responses served with Content-Type other than text/x-content-security-policy, e.g. Content-Type: text/html, or Content-type: image/jpeg
** policy-uri responses served with Content-Type other than text/x-content-security-policy, e.g. Content-Type: text/html, or Content-type: image/jpeg
** report-uri directives which refer to a URI on a different public suffix or base host (ETLD+1) than the protected document, e.g. report-uri http://other.tld/csp-report.cgi
** report-uri directives which refer to a URI on a different public suffix or base host than the protected document, e.g. report-uri http://other.tld/csp-report.cgi
</font>
</font>
<font color="#060">
<font color="#060">
canmove, Confirmed users
1,537

edits