[Webkit-unassigned] [Bug 179728] CSP: Hide nonce values from the DOM

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Oct 15 06:02:07 PDT 2021


https://bugs.webkit.org/show_bug.cgi?id=179728

--- Comment #5 from Philip Jägenstedt <philip at foolip.org> ---
Testing http://wpt.live/content-security-policy/nonce-hiding/script-nonces-hidden.html in Safari Technology Preview 133 I still see failures.

The test doesn't pass in WebKitGTK on wpt.fyi either:
https://wpt.fyi/results/content-security-policy/nonce-hiding/script-nonces-hidden.html?label=master&product=chrome%5Bexperimental%5D&product=firefox%5Bexperimental%5D&product=safari%5Bexperimental%5D&product=webkitgtk&aligned

Maybe this is behind a flag that's only enabled for testing?

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20211015/a0af4fce/attachment-0001.htm>


More information about the webkit-unassigned mailing list