w3c/webappsec-csp Issues

Last updated May 18, 2024, 5:57:08 AM UTC.

This repository doesn't have the Priority: Eventually label that's used to mark an issue as triaged without giving it an SLO. Until that's added, this summary uses heuristics to guess if each issue has been triaged.

Untriaged

Try to triage issues within . [ More Info ]

Issue Title Within SLO On maintainers' plates for Time left Time past SLO
#129 Multiple headers of Allow-CSP-From
#226 Prefer blocking fall-through conditions
#235 Should frame-src control frames with "local scheme"?
#252 What I am doing wrong on this script-src
#292 Potential wrong sha256 example in 'Hash usage for script elements'
#297 Expose host in a 'host' source reference
#314 Clarification of term "parser-inserted"
#384 policy's self-origin for CSP policies inserted by <meta>
#387 http-equiv delivery method: recommend to set after <meta charset="utf-8">?
#388 Is CSPViolationReportBody a funny name?
#396 Use of "Get the effective directive for inline checks" in "Should navigation request of type from source in target be blocked by Content Security Policy?" doesn't seem to make sense
#397 Header parsing and integration with Fetch
#401 Define interaction between script-src / trusted-types
#406 Conflict in CSP reporting specs on nullable fields
#408 Update spec to new IDL syntax for optional dictionaries
#409 Update to constructor operations
#416 Add version number to allow 'non-backwards compatible' CSP[version]-mode
#421 Inconsistent behavior of frame-ancestors versus implementations
#427 `javascript:` navigation directive-name is always null
#428 `unsafe-allow-redirects` and `form-action` interact weirdly
#432 Clarify that report-uri cannot violate mixed-content
#440 host-part matching should allow IPv6 "[::1]" as it does for "127.0.0.1"
#442 Document that line-number and column-number are 1-based in CSP reporting spec
#514 Content-Security-Policy header isn't registered
#521 Editorial: header names and values are byte sequences
#524 should-block-response doesn't forward arguments
#556 Correct the link for CSP3 in the CSP2 Page
#581 Remove initialization hook
#610 CSP: Embedded Enforcement Links for issue 16 and 17 are dead
#624 frame-src using the fetch instead of the navigational check - can end up checking the wrong policies
#632 Some way to allow workers other than URL and strict-dynamic
#635 Does "Is Element Nonceable" apply to non-inline scripts?
#638 `service-worker-src` directive
#643 "Is element nonceable" not applied to non-<script> elements in Chrome?
#660 Request's initiator can't be "fetch"