canmove, Confirmed users
1,537
edits
Line 338: | Line 338: | ||
===No data: URIs unless opted-in to via explicit policy=== | ===No data: URIs unless opted-in to via explicit policy=== | ||
<font color="#a00"> | <font color="#a00"> | ||
* | * User Agents MUST block: | ||
** data: URIs as a source for inline content | ** data: URIs when used as a source for inline content | ||
</font> | </font> | ||
<font color="#060"> | <font color="#060"> | ||
* | * User Agents MUST not block: | ||
** data: URIs as a source for inline content | ** data: URIs when used as a source for inline content explicitly allowed by the protected document's policy. | ||
</font> | </font> | ||
User Agents MUST generate and send a violation report with the fields set appropriately when this base restriction is violated. | |||
===XBL bindings must come from chrome: or resource: URIs=== | ===XBL bindings must come from chrome: or resource: URIs=== |