Changes between Version 3 and Version 4 of Ticket #4866, comment 4


Ignore:
Timestamp:
02/07/2017 07:49:01 AM (3 years ago)
Author:
Lain_13
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #4866, comment 4

    v3 v4  
    33According to changelog #4807 is not yet included in the dev build build 1.12.4.1725. #4770 looks like a likely culprit to me. Especially because child-src were dropped (even though it still works) frame-src doesn't cover workers and worker-src isn't supported yet and wasn't implemented. It clearly leaves workers free from being blocked by CSP. 
    44 
    5 Not sure why you can't reproduce it, though. As I understand CSP in #4807 is only applied to actual scripts loaded from the web. Am I wrong and it's applied to blobs as well? In that case it's the reason why connection is blocked in the master build. In such case we won't need worker-src support at all and can leave #4770 as-is. 
     5Not sure why you can't reproduce it, though. As I understand CSP in #4807 is only applied to actual scripts loaded from the web. Am I wrong and it's applied to blobs as well? In that case it's the reason why connection is blocked in the master build and we won't need worker-src support at all and can leave #4770 as-is. 
    66 
    77BTW, I'd really like to see #4807 in the public dev builds.