Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security feature integration should be expanded for Speculation-Rules header #291

Open
jeremyroman opened this issue Dec 5, 2023 · 0 comments

Comments

@jeremyroman
Copy link
Collaborator

This makes it possible to fetch speculation rules. In particular:

  • the Sec-Fetch-Dest value speculationrules should be specified
  • the CSP integration should be explicit that the script-src directive is respected (but not script-src-elem or script-src-attr) for rule sets externally fetched via the header
  • security considerations should mention that mixed content blocking and CSP apply
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant