Confirmed users
110
edits
m (→Threats) |
m (→Threats) |
||
| Line 70: | Line 70: | ||
| bsterne looking into proposal to extend CSP to support websockets src/origin along with other features | | bsterne looking into proposal to extend CSP to support websockets src/origin along with other features | ||
|- | |- | ||
| HSTS support | | HSTS support {{bug|664284}} | ||
| HSTS currently allows websites to opt-in to secure only communications. Websockets should follow this directive as well. | | HSTS currently allows websites to opt-in to secure only communications. Websockets should follow this directive as well. | ||
| Client browser | | Client browser | ||