[webappsec] Proposed text for jsonp directives

Per ACTION-98 assigned to me, attached find a draft of proposed text for two directives related to JSONP calls.  These directives would allow a protected resource to call legacy JSONP APIs using the src attribute of a script element, but constrain the execution to a safe, CORS-equivalent model. 

Feedback appreciated.

Brad Hill

Received on Saturday, 12 January 2013 01:48:48 UTC