Support by various browsers for various HTTP security headers

Discussion in 'other security issues & news' started by MrBrian, Mar 22, 2014.

Thread Status:
Not open for further replies.
  1. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  2. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  3. gorhill

    gorhill Guest

    It says "Content-Security-Policy" fails for Chromium, while my experience is that it works (HTTPSB uses this for preventing inline javascript).

    I looked into all the headers received when running the test, and nowhere did I see an instance of the header "Content-Security-Policy". So far it looks like the test failed because they actually didn't use the "Content-Security-Policy" header to test the Content Security Policy header... (Firefox "failed" too.)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.