Skip to content

Conversation

@adamraine
Copy link
Contributor

Resolves the issues in #12804 (comment)

In addition to the updates in that comment:

  • We check for wildcards and plain URL schemes (e.g. https:) in object-src, script-src, and base-uri. This is meant to replace our enforcement of object-src 'none'.
  • UI strings for missing object-src and host allowlist have been updated.

@adamraine adamraine requested a review from a team as a code owner August 27, 2021 01:04
@adamraine adamraine requested review from patrickhulce and removed request for a team August 27, 2021 01:04
@google-cla google-cla bot added the cla: yes label Aug 27, 2021
@adamraine adamraine merged commit c9c6c55 into master Aug 31, 2021
@adamraine adamraine deleted the csp-evaulator-bump branch August 31, 2021 16:35
satya-nutella pushed a commit to satya-nutella/lighthouse that referenced this pull request Sep 7, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants