[w3ctag/design-reviews] TAG review request of the CSP feature 'unsafe-hashes' (#291)

Hello TAGļ¼

I'm requesting a TAG review of:

  - Name: 'unsafe-hashes'
  - Specification URL: https://w3c.github.io/webappsec-csp/#unsafe-hashes-usage
  - Explainer, Requirements Doc, or Example code: https://docs.google.com/document/d/1_nYS4gWYO2Oh8rYDyPglXIKNsgCRVhmjHqWlTAHst7c/edit?usp=sharing
  - Tests: recently added so wpt.fyi has not caught up yet
https://github.com/web-platform-tests/wpt/pull/11457
https://wpt.fyi/results/content-security-policy/unsafe-hashes
  - Primary contacts: andypaicu@chromium.org, mkwst@chromium.org

Further details (optional):

  - Relevant time constraints or deadlines: noe
  - [ ] I have read and filled out the [Self-Review Questionnare on Security and Privacy](https://www.w3.org/TR/security-privacy-questionnaire/). The [assessment is here](url).
  - [ ] I have reviewed the TAG's [API Design Principles](https://w3ctag.github.io/design-principles/)
^ I have skimmed the two points above but I don't think they apply to this type of feature.

We'd prefer the TAG provide feedback as (please select one):

  - [ ] open issues in our Github repo for each point of feedback
  - [ ] open a single issue in our Github repo for the entire review
  - [x] leave review feedback as a comment in this issue and @-notify [github usernames]


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/291

Received on Friday, 22 June 2018 15:51:14 UTC