User Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36 Steps to reproduce: I issue a CSP header that contains both the child-src and frame-src directive. These directives contain the same values for backwards compatibility. You can see this in my current CSP header on https://scotthelme.co.uk Actual results: Firefox gives me the following warning: Content Security Policy: Directive 'frame-src' has been deprecated. Please use directive 'child-src' instead. Expected results: I am already using the child-src directive so this warning is redundant. Firefox should simply disregard the frame-src directive and use the provided child-src directive.
Component: Untriaged → DOM: Security
Product: Firefox → Core
Status: UNCONFIRMED → RESOLVED
Last Resolved: 2 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 1288896
You need to log in before you can comment on or make changes to this bug.