ISSUE-8: Identify proper behavior for html added via plugins / object tag
Identify proper behavior for html added via plugins / object tag
- State:
- CLOSED
- Product:
- CSP Level 1
- Raised by:
- Opened on:
- 2011-11-22
- Description:
- Related Actions Items:
ACTION-19 on Adam Barth to Clarify policy applied for html loaded via object tag - due 2012-01-03, closed- Related emails:
- No related emails
Related notes:
No language to this effect yet. Section 3.3 of CSP includes the text:
"Enforcing a CSP policy should not interfere with the operation of user-supplied scripts such as third-party user-agent add-ons and JavaScript bookmarklets."
This may be confusing as the distinction between a "user-agent add-on" and a "plug in" is not explicit.
Display change log