You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@arturjanc suggested that an attacker might abuse the same-origin carveout for the csp attribute's enforcement by using default-src 'none'; report-uri https://evil.com/. Think about that.
From @mikewest on October 12, 2016 9:22
@arturjanc suggested that an attacker might abuse the same-origin carveout for the
csp
attribute's enforcement by usingdefault-src 'none'; report-uri https://evil.com/
. Think about that.Copied from original issue: w3c/webappsec-csp#126
The text was updated successfully, but these errors were encountered: