Open Bug 1220001 Opened 9 years ago Updated 2 years ago

Unicode normalization should not happen in CSP

Categories

(Core :: DOM: Security, defect, P3)

defect

Tracking

()

People

(Reporter: francois, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-backlog3])

As discussed on the webappsec list, Unicode normalization should not happen:

  https://lists.w3.org/Archives/Public/public-webappsec/2015Oct/0101.html
  https://lists.w3.org/Archives/Public/public-webappsec/2015Oct/0102.html

The web-platform tests have been updated to cover this:

  https://github.com/w3c/web-platform-tests/pull/2287
Priority: -- → P3
Whiteboard: [domsecurity-backlog]
Whiteboard: [domsecurity-backlog] → [domsecurity-backlog3]
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.