Summary: The Connection-Allowlist header allows web developers to limit the servers a website can communicate with. This can be used to prevent data exfiltration attacks.
Bug: Bug 2062159 <https://bugzilla.mozilla.org/show_bug.cgi?id=2062159> Specification: https://wicg.github.io/connection-allowlists/ Standards Body: This specification is supposed to be adopted by the W3C Web Application Security Working Group. Platform Coverage: All Preference: security.connection_allowlists.enabled DevTools Bug: None (The header would automatically show up) Extensions Bug: n/a Use Counter: tbd (Bug 2073432 <https://bugzilla.mozilla.org/show_bug.cgi?id=2073432>) Standards-Positions Discussion: positive <https://github.com/mozilla/standards-positions/issues/1322> Other Browsers: - Blink: shipped (since 152 <https://chromestatus.com/feature/5175745573945344>) - WebKit: no signal ( https://github.com/WebKit/standards-positions/issues/583) web-platform-tests: https://wpt.fyi/results/connection-allowlist -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-platform/CA%2BCWiYgeNS1-RhAasZ%3DfAp3c2iwvw_bui%2BeqG42ok0mHePaymQ%40mail.gmail.com.
