Talk:Security/CSP/Spec: Difference between revisions

m
Line 182: Line 182:


So either we need a directive to control form actions, or we shouldn't subject the form actions to CSP at all like anchor-based links (not even the allow directive).
So either we need a directive to control form actions, or we shouldn't subject the form actions to CSP at all like anchor-based links (not even the allow directive).
Also, <tt>form-action</tt> is not part of the spec yet... but the more it is discussed, the more I'm starting to think it's useful.
-[[User:Sidstamm|Sid]]
-[[User:Sidstamm|Sid]]


canmove, Confirmed users
1,537

edits