Issue metadata
Sign in to add a comment
|
Deprecate and remove CSP's `reflected-xss` directive. |
||||||||||||||||||||||||||||||||||||||||||
Issue descriptionEarly drafts of CSP2 contained a `reflected-xss` directive, which is little more than syntactic sugar for the `X-XSS-Protection` header. It offered no additional functionality beyond that header, just a better syntax. I shipped our implementation as part of shipping CSP2 (https://groups.google.com/a/chromium.org/forum/#!msg/blink-dev/wToP6b04zVE/imuPatGy3awJ). I should have undone that in 2015 when we dropped the directive from the CR draft. I'd like to undo it now
,
Nov 18 2016
,
Feb 23 2017
|
|||||||||||||||||||||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||||||||||||||||||||
Comment 1 by bugdroid1@chromium.org
, Oct 24 2016