Re: Remove paths from CSP?

On Wed, Feb 12, 2014 at 11:55 AM, Egor Homakov <homakov@gmail.com> wrote:

> Author of the article here :) I believe killing paths is killing point of
> CSP, furthermore, I'd like to have ?query whitelisted too!
>

Really?

Neither GitHub nor Facebook use paths in their policies today. I don't
actually know of any service making use of the feature. I'd be happy to be
wrong about that if someone has examples.


> We should patch the whole right where it happens - leakage. We should make
> it impossible to detect whether CSP has blocked a resource. Fake
> width/height of images, fire onload events, just like nothing happened.
>

As noted in the last email, I don't honestly think this is possible.

-mike

Received on Wednesday, 12 February 2014 14:44:04 UTC