Skip to content

CSP sources no URL scheme is specified note #2460

@swilliamsui

Description

@swilliamsui

MDN URL: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-src#sources

What information was incorrect, unhelpful, or incomplete?

How protocols without a scheme are treated is unclear. The frame-ancestors#sources note in yellow is much more clear.

image

Specific section or headline?

"Sources" -> "< host source >"

What did you expect to see?

Yellow box should be applied to all relevant locations.

Did you test this? If so, how?

N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions