Conversation
|
The build error appears to be preexisting. |
|
The build error should be fixed with #777. |
This upstreams the monkeypatches from https://wicg.github.io/nav-speculation/speculation-rules.html#content-security-policy. At a high level, the additions are: - A new directive, `inline-speculation-rules`, which can be used if developers want to block inline JavaScript `<script>`s but allow inline `<script type=speculationrules>`s. This is done by introducing a new script type, `script speculationrules`, to sit alongside the existing `script` and `script attribute` types; HTML passes this new value in. - Handling of the new `"speculationrules"` request destination, which is used by the `Speculation-Rules` HTTP header. It cannot be blocked by CSP.
16bb13b to
8c2dcb5
Compare
|
Rebased! |
|
This is ready to merge! |
mikewest
left a comment
There was a problem hiding this comment.
This LGTM, and as it's landed in HTML it should meet the requirements we're starting to pull together for additions to CSP.
I'll wait a bit for @antosart to have any feedback, but I'm comfortable merging this at this point.
Thanks!
|
This looks good to me, too, but see whatwg/fetch#1841 (comment). Would it make sense to provide more context and link to some reasoning on the decision of gating |
Well I don't think you're going to need that explanation, because the new PR whatwg/fetch#1952 does not exempt the But it looks like this PR is itself replaced by #808. |
This upstreams the monkeypatches from https://wicg.github.io/nav-speculation/speculation-rules.html#content-security-policy. At a high level, the additions are:
A new directive,
inline-speculation-rules, which can be used if developers want to block inline JavaScript<script>s but allow inline<script type=speculationrules>s. This is done by introducing a new script type,script speculationrules, to sit alongside the existingscriptandscript attributetypes; HTML passes this new value in.Handling of the new
"speculationrules"request destination, which is used by theSpeculation-RulesHTTP header. It cannot be blocked by CSP.This should be merged a bit after whatwg/html#11426. Otherwise it will reference the WICG draft.
Preview | Diff