canmove, Confirmed users
1,537
edits
| Line 90: | Line 90: | ||
| * Vulnerability types mitigated: | * Vulnerability types mitigated: | ||
| *# data: URL script injection | *# data: URL script injection | ||
| * data: URIs can be re-enabled by adding "data:" as a source to any source directive.  For example: <tt>img-src data: https://my-host.com</tt>. | |||
| ==XBL bindings must come from chrome: or resource: URIs== | ==XBL bindings must come from chrome: or resource: URIs== | ||