#15727: out of the box support for CSP would totally rock!
-----------------------------------------+-----------------------------
               Reporter:  db.pub.mail@…  |        Owner:  nobody
                   Type:  New feature    |       Status:  new
              Milestone:                 |    Component:  HTTP handling
                Version:  1.2            |     Severity:  Normal
             Resolution:                 |     Keywords:
           Triage Stage:  Someday/Maybe  |    Has patch:  0
    Needs documentation:  0              |  Needs tests:  0
Patch needs improvement:  0              |
-----------------------------------------+-----------------------------

Comment (by d1b):

 Well it would be a real nice to have. I sent an email reply but it was
 blocked :/
 Django hasn't been 'xss free' and a new template tag could be added to
 transform inline js into js included and served from a location which the
 CSP policy allows.

-- 
Ticket URL: <http://code.djangoproject.com/ticket/15727#comment:5>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en.

Reply via email to