[Webkit-unassigned] [Bug 179728] CSP: Hide nonce values from the DOM

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Nov 10 00:29:39 PST 2020


https://bugs.webkit.org/show_bug.cgi?id=179728

Philip Jägenstedt <philip at foolip.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |philip at foolip.org

--- Comment #3 from Philip Jägenstedt <philip at foolip.org> ---
A number of tests around this are now failing in only Safari:
https://wpt.fyi/results/content-security-policy/nonce-hiding?label=master&label=experimental&product=chrome&product=firefox&product=safari&aligned

A trivial demo of it is here: https://software.hixie.ch/utilities/js/live-dom-viewer/saved/8672

(I found my way here from looking into https://github.com/mdn/browser-compat-data/pull/7303.)

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20201110/97be6ad1/attachment-0001.htm>


More information about the webkit-unassigned mailing list