Closed
Bug 1059223
Opened 11 years ago
Closed 10 years ago
Restrict CSP to trusted domains for Trusted Hosted Apps
Categories
(Core Graveyard :: DOM: Apps, defect)
Tracking
(Not tracked)
RESOLVED
INVALID
2.1 S4 (12sep)
People
(Reporter: mattias.ostergren, Unassigned)
References
Details
Implement and enable verification of CSP policies source list in the manifest.
CSP element MUST contain 'script-src' and 'style-src' directives restricted to 'self' and a list of trusted domains. These domains MUST have verified https certificates.
Reporter | ||
Updated•11 years ago
|
Updated•11 years ago
|
Whiteboard: [2.1-feature-qa+]
Reporter | ||
Comment 1•10 years ago
|
||
Current understanding is that this bug is redundant. See bug 1059221
Updated•7 years ago
|
Product: Core → Core Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•