[websec] fyi: Unofficial Draft of Content Security Policy (CSP)

=JeffH <Jeff.Hodges@KingsMountain.com> Thu, 24 March 2011 19:48 UTC

Return-Path: <Jeff.Hodges@KingsMountain.com>
X-Original-To: websec@core3.amsl.com
Delivered-To: websec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id EDEA328C0ED for <websec@core3.amsl.com>; Thu, 24 Mar 2011 12:48:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.729
X-Spam-Level:
X-Spam-Status: No, score=-101.729 tagged_above=-999 required=5 tests=[AWL=-0.547, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, URIBL_RHS_DOB=1.083, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TEnV-U7iGGSb for <websec@core3.amsl.com>; Thu, 24 Mar 2011 12:48:42 -0700 (PDT)
Received: from oproxy3-pub.bluehost.com (oproxy3-pub.bluehost.com [69.89.21.8]) by core3.amsl.com (Postfix) with SMTP id DB54B28C0D6 for <websec@ietf.org>; Thu, 24 Mar 2011 12:48:42 -0700 (PDT)
Received: (qmail 12940 invoked by uid 0); 24 Mar 2011 19:50:17 -0000
Received: from unknown (HELO box514.bluehost.com) (74.220.219.114) by oproxy3.bluehost.com with SMTP; 24 Mar 2011 19:50:16 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=kingsmountain.com; h=Received:Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:Content-Type:Content-Transfer-Encoding:X-Identified-User; b=m+GFqeUu6mxMyzEEEgrvh4zdUxJg65qkIQzFU2zTs//o79W98AQ8vAWiVk+uCRl77bHN5OJiOaZm8CIeQTB+QM4Nxo946L7Blhe1rcxtHZFwZGlnb0YU0KMSb7JmHIUZ;
Received: from outbound4.ebay.com ([216.113.168.128] helo=[10.244.137.235]) by box514.bluehost.com with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.69) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1Q2qXv-0000cv-Nl for websec@ietf.org; Thu, 24 Mar 2011 13:50:15 -0600
Message-ID: <4D8BA070.3040706@KingsMountain.com>
Date: Thu, 24 Mar 2011 12:50:08 -0700
From: =JeffH <Jeff.Hodges@KingsMountain.com>
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.14) Gecko/20110223 Thunderbird/3.1.8
MIME-Version: 1.0
To: IETF WebSec WG <websec@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Identified-User: {11025:box514.bluehost.com:kingsmou:kingsmountain.com} {sentby:smtp auth 216.113.168.128 authed with jeff.hodges+kingsmountain.com}
Subject: [websec] fyi: Unofficial Draft of Content Security Policy (CSP)
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Mar 2011 19:48:44 -0000

Of possible interest:

CSP is being discussed here..

http://lists.w3.org/Archives/Public/public-web-security/

My recent review..

http://lists.w3.org/Archives/Public/public-web-security/2011Mar/0039.html


Original CSP-as-unofficial-"w3c format"-draft announcements..

------- Forwarded Messages

Date:    Thu, 03 Mar 2011 10:17:47 -0800
From:    Brandon Sterne <bsterne@mozilla.com>
To:      "public-web-security@w3.org" <public-web-security@w3.org>
Subject: Unofficial Draft of Content Security Policy

Hello all,

Apologies for the delays in getting this published.  You can find the
first Unofficial Draft of the Content Security Policy specification here:
https://dvcs.w3.org/hg/content-security-policy/raw-file/bcf1c45f312f/csp-unoffi
cial-draft-20110303.html

I hope you will find the new format well-organized and reflective of our
discussion so far.  While this document will likely remain in Unofficial
Draft status until we get our charter reviewed and accepted, in the
meantime this it should provide a good basis for further discussions.  I
look forward to receiving your feedback.

Best,
Brandon


------- Message 2

Date:    Tue, 15 Mar 2011 17:07:09 -0700
From:    Brandon Sterne <bsterne@mozilla.com>
To:      "public-web-security@w3.org" <public-web-security@w3.org>
Subject: [Content Security Policy] unofficial draft revision

Hello all,

Just wanted to let you know that I pushed a new revision of the CSP
unofficial draft:
https://dvcs.w3.org/hg/content-security-policy/raw-file/tip/csp-unofficial-draf
t-20110315.html

This revision added CSS image loading to the image-src directive and
converted the grammar to ABNF.  Many thanks to Adam for helping me with
some of the trickier aspects of the grammar conversion.

You can see just the changes here if you're interested:
https://dvcs.w3.org/hg/content-security-policy/diff/1a29ed0d9fdc/csp-specificat
ion.dev.html

Cheers,
Brandon


------- End of Forwarded Messages