| Summary: | Invalid characters in HTTP Content-Security-Policy value doesn't impact the CSP | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | karl <karl+webkit> |
| Component: | Page Loading | Assignee: | Nobody <webkit-unassigned> |
| Status: | RESOLVED WORKSFORME | ||
| Severity: | Normal | CC: | beidson |
| Priority: | P2 | ||
| Version: | Safari Technology Preview | ||
| Hardware: | Mac (Intel) | ||
| OS: | macOS 10.15 | ||
| URL: | https://www.mollysastrology.com | ||
|
Description
karl
2022-03-03 04:32:46 PST
Opened on https://bugs.webkit.org/show_bug.cgi?id=237419 https://bugzilla.mozilla.org/show_bug.cgi?id=1757913 https://bugs.chromium.org/p/chromium/issues/detail?id=1302617 So this is already a known bug on Firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1570722 And it was discussed on https://github.com/w3c/webappsec-csp/issues/473 The behavior of Blink and WebKit is right. |