[webkit-dev] Request for position on import maps
rniwa at webkit.org
Tue Oct 27 22:28:00 PDT 2020
On Tue, Oct 27, 2020 at 2:23 PM Domenic Denicola <d at domenic.me> wrote:
> Chrome is working toward shipping this in an imminent release, and we'd love any thoughts or contributions from the WebKit community.
How does this feature supposed to work with CSP subresource integrity?
As far as I've read various specs and the proposal, it's not currently
possible to specify any integrity checks on modules loaded via import
this. This is a pretty serious downside because it would mean that any
remote server ever referenced by an import map becomes a security
liability for a given website. It's a lot worse compared to normal
scripts because of the action-at-a-distance of import maps. There is
no indication that a given module import could involve access to
cross-origin servers isn't obvious from where the import statement
- R. Niwa
More information about the webkit-dev