Comments on the Content Security Policy specification

2009-07-16 Thread Ian Hickson
browsers would support this, and during the transition period, browser sniffing would be fine. (If we do add the advertisment, we can never remove it, even if all browsers support it -- just like we can't remove the "Mozilla/4.0" part of every browser's UA string now.) -- I

Re: Comments on the Content Security Policy specification

2009-07-29 Thread Ian Hickson
On Thu, 16 Jul 2009, Bil Corry wrote: > Ian Hickson wrote on 7/16/2009 5:51 AM: > > I think that this complexity, combined with the tendency for authors > > to rely on features they think are solvign their problems, would > > actually lead to authors writing polic

Re: Comments on the Content Security Policy specification

2009-08-11 Thread Ian Hickson
On Thu, 30 Jul 2009, Gervase Markham wrote: > On 29/07/09 23:23, Ian Hickson wrote: > > * Remove external policy files. > > I'm not sure how that's a significant simplification; the syntax is > exactly the same just with an extra level of indirection, and