This needs investigation and I have yet to figure out why. It doesn't seem to be related to the loadType, but I might be wrong :)
I suppose in ::OnStreamComplete() we have to check if the contentpolicyType is TYPE_SCRIPT_PRELOAD, and if that is the case then we have to query and consult the preloadCSP |principal->GetPreloadCsp()| instead of the actual CSP. Oh joy!
Assignee: nobody → ckerschb
Status: NEW → ASSIGNED
Whiteboard: [domsecurity-backlog] → [domsecurity-active]
Attachment #8767150 - Flags: review?(francois) → review+
Attachment #8767152 - Flags: review?(francois) → review+
Pushed by email@example.com: https://hg.mozilla.org/integration/mozilla-inbound/rev/2373b4f2f321 CSP require-sri-for does not block when CSP is in meta tag r=francois https://hg.mozilla.org/integration/mozilla-inbound/rev/fe2cd5c40e73 Test require-sri-for in meta tag r=francois
You need to log in before you can comment on or make changes to this bug.