You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Are you asking if they are required because it's hard to use an HTTP header (shouldn't be)?
Not because of that. Because I wasn't sure it's a relevant scenario for trusted-types. But since it's a possible scenario, there should be tests.
mbrodesser-Igalia
changed the title
Are WPTs for CSP sandbox allow-scripts required?
Add WPTs for CSP sandbox allow-scripts combined with Trusted Types
May 13, 2024
https://w3c.github.io/webappsec-csp/#directive-sandbox
The
sandbox
directive is ignored when delivered via a<meta>
tag.The text was updated successfully, but these errors were encountered: