Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

frame-src and child-src #10

Open
Munter opened this issue Mar 4, 2017 · 0 comments
Open

frame-src and child-src #10

Munter opened this issue Mar 4, 2017 · 0 comments

Comments

@Munter
Copy link
Owner

Munter commented Mar 4, 2017

frame-src was a part of CSP1, but deprecated in CSP2 in favor of child-src.

This seems to have been undone in CSP3, so frame-src is undeprecated.

I can see how this might lead to confusion in authoring a CSP.

Is there an objectively correct thing express-legacy-csp could do to help authors by renaming these directives according to the support in the version of the policy served to browsers with differing support?

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant