You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The first check for all script-src-elem checks, however, is to check if the request is script-like as defined by fetch. Fetch does not define XSLT as a script-like check https://fetch.spec.whatwg.org/#request-destination-script-like, which makes the entire thing a no-op always-allow rule.
Is that the intent here?
The text was updated successfully, but these errors were encountered:
According to https://www.w3.org/TR/CSP/#effective-directive-for-a-request, XSLT documents should be checked as script.
The first check for all script-src-elem checks, however, is to check if the request is script-like as defined by fetch. Fetch does not define XSLT as a script-like check https://fetch.spec.whatwg.org/#request-destination-script-like, which makes the entire thing a no-op always-allow rule.
Is that the intent here?
The text was updated successfully, but these errors were encountered: