Restrict usage of synchronous XMLHttpRequest by feature policy
Categories
(Core :: DOM: Networking, enhancement, P3)
Tracking
()
People
(Reporter: iclelland, Assigned: twisniewski)
References
(Blocks 2 open bugs)
Details
(Keywords: dev-doc-needed, site-compat, Whiteboard: [necko-triaged])
Attachments
(1 file, 1 obsolete file)
Updated•7 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Assignee | ||
Comment 1•6 years ago
|
||
Updated•6 years ago
|
Assignee | ||
Comment 2•6 years ago
|
||
It seems we're not likely to move on this anytime soon, but I figured I might as well attach my patch here just in case.
Comment 3•5 years ago
|
||
This feature won't be supported in the allow
attribute. It will instead be part of something called "Document Policies", see https://github.com/w3c/webappsec-feature-policy/blob/master/document-policy-explainer.md. This is still under design so not really ready for implementation.
Updated•5 years ago
|
Updated•2 years ago
|
Assignee | ||
Comment 4•1 year ago
|
||
Comment on attachment 9050633 [details] [diff] [review]
patch (do not land).diff
Given that feature policy hasn't budged in four years, is still preffed off in Firefox by default, and the other browsers have been passing the WPTs.. I don't see any reason why we shouldn't just implement this in case we turn on the pref at some point. I'll post a fresh patch shortly.
Assignee | ||
Comment 5•1 year ago
|
||
Updated•1 year ago
|
Updated•8 months ago
|
Updated•7 months ago
|
Description
•