Security/CSP/BaseModule: Difference between revisions

Line 11: Line 11:
future-rule            = (anything but ",")
future-rule            = (anything but ",")
known-rule              = *SP directive [ 1*SP origin-list ] *SP
known-rule              = *SP directive [ 1*SP origin-list ] *SP
directive              = (see below)
directive              = (see individual modules)
origin-list            = origin-descriptor [ 1*SP origin-list]
origin-list            = origin-descriptor [ 1*SP origin-list]
origin-descriptor      = "none" / "self" / "*" / [scheme "://"] host-descriptor
origin-descriptor      = "none" / "self" / "*" / [scheme "://"] host-descriptor
Line 17: Line 17:
qualified-host-name    = dns-label "." host-name
qualified-host-name    = dns-label "." host-name
host-name              = dns-label ["." host-name]
host-name              = dns-label ["." host-name]
</pre>
</pre>  
The browser MUST ignore any X-Content-Security-Policy header fields occurring in an HTML meta tag or in the Trailer headers. &nbsp;The semantics of these directives are described in the following section.
The browser MUST ignore any X-Content-Security-Policy header fields occurring in an HTML meta tag or in the Trailer headers. &nbsp;The semantics of these directives are described in the following section.


118

edits