CSP hash reporting keywords #430
Labels
topic: security
venue: W3C Web Application Security WG
Proposal is being reviewed in the W3C's Web Application Security WG (aka WebAppSec)
WebKittens
@annevk
Title of the proposal
Hash reporting for scripts
URL to the spec
w3c/webappsec-csp#693
URL to the spec's repository
https://github.com/w3c/webappsec-csp/
Issue Tracker URL
No response
Explainer URL
w3c/webappsec-csp#693 (comment)
TAG Design Review URL
w3ctag/design-reviews#1020
Mozilla standards-positions issue URL
mozilla/standards-positions#1129
WebKit Bugzilla URL
No response
Radar URL
No response
Description
This feature adds a new CSP directive "report-hash", which triggers a new reporting type "csp-hash-report".
It reports hashes for (same-origin or CORS enabled) scripts that are loaded in the context of the document (regardless of their "integrity" attribute), and sends reports about them.
Those reports enable developers to:
The text was updated successfully, but these errors were encountered: