Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clarify that integrity metadata must be non-empty #425

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

bakkot
Copy link

@bakkot bakkot commented Mar 18, 2020

There is a Note which reads

Note: Here, we verify only that the request contains a set of integrity metadata which is a subset of the hash-source source expressions specified by directive. We rely on the browser’s enforcement of Subresource Integrity [SRI] to block non-matching resources upon response.

But that's misleading: integrity metadata can be an empty set, which is a subset of every set, but that is not sufficient to meet these verification requirements.

For IPR I would consider this to be non-substantive.


Preview | Diff

Base automatically changed from master to main February 16, 2021 23:21
@w3cbot
Copy link

w3cbot commented Feb 18, 2021

sideshowbarker marked as non substantive for IPR from ash-nazg.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants