3 ms·
The header is 9 days old, and now Chrome is sending it by default: https://github.com/w3c/webappsec/commit/eeac3922418bfa6cb254071c74ddd962ee418c80#diff-3545c71
by tomsommer 11y ago
The header is 9 days old, and now Chrome is sending it by default: https://github.com/w3c/webappsec/commit/eeac3922418bfa6cb254071c74ddd962ee418c80#diff-3545c71e29140b0ee305d62eefac12f4 https://github.com/w3c/webappsec/commit/eeac3922418bfa6cb254...
Header bloat, ~28 extra bytes per request from every Chrome user in the world.
The whole idea of the header is odd, it should be something the server could send to the client, if needed, not something the client should announce support for.
Crazy indeed.
- MichaelGG 11y agoYeah I read the draft and the rationale seems very weak. What's wrong with just sending the Content-Security-Policy header in responses and letting UAs do what they will? Nothing. Same as redirecting to HTTPS if you support it. But for some reason, they had to combine things and want to know if it's "safe" to use HTTPS. They didn't appear to list any real scenarios for this behavior. (Maybe there are, it's not readily apparent though.)