'upgrade-insecure-requests; block-all-mixed-content' should be identical to 'upgrade-insecure-requests' |
|||||
Issue descriptionCurrently, we have a few holes in our 'upgrade-insecure-requests' implementation (mostly around redirects). Once we resolve those, we should be able to get away with a simple tri-state policy state, rather than the multiple flags we're currently storing on SecurityContext (and replicating from frame to frame).
,
Jun 7 2016
,
Nov 18 2016
,
Nov 10 2017
,
Feb 18 2018
|
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mkwst@chromium.org
, Jun 6 2016