Skip to content

Add an SRI control as either a CSP directive or a new header #23

@joelweinberger

Description

@joelweinberger

Per the suggestion in https://lists.w3.org/Archives/Public/public-webappsec/2015Dec/0045.html, it might make sense to extend CSP with a directive to control SRI. For example, we could have an sri-options directive that can take options like scripts-require-sri. This would also be a good place to eventually have a report-only option for SRI.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions