Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

require-sri-for CSP directive #1048

Open
1 task done
yoavweiss opened this issue Feb 6, 2025 · 0 comments
Open
1 task done

require-sri-for CSP directive #1048

yoavweiss opened this issue Feb 6, 2025 · 0 comments

Comments

@yoavweiss
Copy link

yoavweiss commented Feb 6, 2025

こんにちは TAG-さん!

I'm requesting a TAG review of the require-sri-for CSP directive.

Subresource-Integrity (SRI) enables developers to make sure the assets they intend to load are indeed the assets they are loading. But there's no current way for developers to be sure that all of their scripts are validated using SRI.

The require-sri-for CSP directive gives developers the ability to assert that every resource of a given type needs to be integrity checked. If a resource of that type is attempted to be loaded without integrity metadata, that attempt will fail and trigger a CSP violation report.

Further details:

  • I have reviewed the TAG's Web Platform Design Principles
  • Previous early design review, if any: N/A
  • Relevant time constraints or deadlines: I'd like to ship this soon
  • The group where the work on this specification is currently being done: WebAppSec
  • The group where standardization of this work is intended to be done (if different from the current group):
  • Major unresolved issues with or opposition to this specification:
  • This work is being funded by: Shopify
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant