|
|
|
|
|
by tptacek
6094 days ago
|
|
I don't really get CSP. Without changing anything in the browser, application developers --- the only people who can really use CSP --- can already create policies that say where dynamic code should or shouldn't be allowed. The problem is that modern web apps are riddled with places that need enough dynamicism that blunt filtering won't work. |
|
http://people.mozilla.org/~bsterne/content-security-policy/d...