3 ms·
I think this would look better as some kind of <meta> tag inside the HTML document. I think that the document itself should have knowledge about its security r
by JD557 8y ago
I think this would look better as some kind of <meta> tag inside the HTML document.
I think that the document itself should have knowledge about its security requirements (the "allow" field in <iframe> tags requires this), so it seems awkward to have part of the responsibility in the HTTP server and another part in the HTML document.
- klodolph 8y agoAs a website operator, I should be able to have some guarantees about the security of my site without auditing every single piece of HTML, JavaScript, and CSS. That might be far from a trivial task if my site has user-generated content... beyond forums, there are also blogs and CMSs. HTML, JS, and CSS are fast moving targets and something that is safe today could easily have security implications down the road when a new feature arrives. This has happened before and it will happen again.