canmove, Confirmed users
1,537
edits
Line 349: | Line 349: | ||
===XBL bindings must come from chrome: or resource: URIs=== | ===XBL bindings must come from chrome: or resource: URIs=== | ||
''NOTE: this is currently Firefox-Specific, but related behavior in other User Agents should also be limited.'' | |||
<font color="#a00"> | <font color="#a00"> | ||
* | * User Agents MUST block: | ||
** XBL bindings loaded via any protocol other than chrome: or resource: | ** XBL bindings loaded via any protocol other than chrome: or resource: | ||
</font> | </font> | ||
<font color="#060"> | <font color="#060"> | ||
* | * User Agents MUST not block: | ||
** XBL bindings loaded via the chrome: or resource: protocols | ** XBL bindings loaded via the chrome: or resource: protocols | ||
</font> | </font> | ||
User Agents MUST generate and send a violation report with the fields set appropriately when this base restriction is violated. | |||
==Restrictions on policy-uri and report-uri== | ==Restrictions on policy-uri and report-uri== |