Bug 99250 - CSP source expressions should support paths at file-level granularity.
: CSP source expressions should support paths at file-level granularity.
Status: RESOLVED FIXED
: WebKit
WebCore Misc.
: 528+ (Nightly build)
: Unspecified Unspecified
: P2 Normal
Assigned To:
:
: WebExposed
:
: 85558
  Show dependency treegraph
 
Reported: 2012-10-13 08:40 PST by
Modified: 2012-10-15 10:33 PST (History)


Attachments
Patch (10.66 KB, patch)
2012-10-13 08:49 PST, Mike West
no flags Review Patch | Details | Formatted Diff | Diff


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2012-10-13 08:40:02 PST
As per https://dvcs.w3.org/hg/content-security-policy/rev/c29f8817f682, and discussion at http://lists.w3.org/Archives/Public/public-webappsec/2012Sep/0099.html:

* 'example.com/js' matches a file named 'js'
* 'example.com/js/' matches all files under a directory named 'js' (note the trailing slash)
* 'example.com/js/file.js' matches only a file named 'file.js' inside a directory named 'js'
------- Comment #1 From 2012-10-13 08:49:18 PST -------
Created an attachment (id=168555) [details]
Patch
------- Comment #2 From 2012-10-14 22:58:30 PST -------
This seems like a good resolution.
------- Comment #3 From 2012-10-14 23:59:12 PST -------
(From update of attachment 168555 [details])
Thanks, throwing this in the queue.
------- Comment #4 From 2012-10-15 10:33:14 PST -------
(From update of attachment 168555 [details])
Clearing flags on attachment: 168555

Committed r131317: <http://trac.webkit.org/changeset/131317>
------- Comment #5 From 2012-10-15 10:33:17 PST -------
All reviewed patches have been landed.  Closing bug.