5 ms·
Why is this better than the Content Security Policy header where you can specify a hash or the hash attribute on a script tag?
by ff7c11 11y ago
Why is this better than the Content Security Policy header where you can specify a hash or the hash attribute on a script tag?
- sarciszewski 11y agoYou can enable it via editing HTML rather than altering the HTTP headers.
- detaro 11y agothat only works on inlined scripts, not on external references.
- Someone1234 11y agoI'm a big fan of CSP, but even I have to admit that the CSP is quite large/expensive for a HTTP header field. It might be different for other sites/stacks but on ours we deliver CSP at the whole site level, meaning it is delivered with every response we send. Script integrity is only sent when that specific script is used, and it means our workflow doesn't have to change to rewrite a HTTP header dynamically with each page (based on which scripts are or aren't on that specific page). I legitimately have no idea how I would implement CSP with hashes for the scripts on that specific page. It would require me to actually patch the software stack upstream. I do however know exactly how I'd use the integrity field on a script block and could implement it with just raw HTML. PS - Not to mention that few browsers support level 2: http://caniuse.com/#feat=contentsecuritypolicy2 http://caniuse.com/#feat=contentsecuritypolicy2
- codedokode 11y agoCSP header doesn't need to be added for every response, e.g. for images or JS files.