Skip to content

Deprecate CSP block-all-mixed-content directive#7664

Merged
ddbeck merged 1 commit intomdn:masterfrom
w3c:sideshowbarker/csp-block-all-mixed-content-deprecate
Dec 14, 2020
Merged

Deprecate CSP block-all-mixed-content directive#7664
ddbeck merged 1 commit intomdn:masterfrom
w3c:sideshowbarker/csp-block-all-mixed-content-deprecate

Conversation

@sideshowbarker
Copy link
Copy Markdown
Member

This change marks the CSP block-all-mixed-content directive as deprecated:true, per the current version of the CSP spec at https://w3c.github.io/webappsec-mixed-content/#obsolescences:

This specification renders the Mixed Content §4 Strict Mixed Content Checking mode and the block-all-mixed-content CSP directive obsolete, because all mixed content is now blocked if it can’t be autoupgraded.


MDN article already updated.

This change marks the CSP block-all-mixed-content directive as
deprecated:true, per the current version of the CSP spec at
https://w3c.github.io/webappsec-mixed-content/#obsolescences:

> This specification renders the Mixed Content §4 Strict Mixed Content
> Checking mode and the block-all-mixed-content CSP directive obsolete,
> because all mixed content is now blocked if it can’t be autoupgraded.
@github-actions github-actions bot added the data:http Compat data for HTTP features. https://developer.mozilla.org/docs/Web/HTTP label Dec 12, 2020
Copy link
Copy Markdown
Contributor

@ddbeck ddbeck left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@ddbeck ddbeck merged commit 531ebb0 into mdn:master Dec 14, 2020
@sideshowbarker sideshowbarker deleted the sideshowbarker/csp-block-all-mixed-content-deprecate branch December 15, 2020 04:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

data:http Compat data for HTTP features. https://developer.mozilla.org/docs/Web/HTTP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants