Skip to content

COEP still doesn't check for HTTPS #6328

@zcorpan

Description

@zcorpan

https://html.spec.whatwg.org/commit-snapshots/0f2615317684a837150f5fc76b216a66f91427d9/#the-headers-2

To obtain an embedder policy from a response response:​

In #5164 I noted that COOP required a secure context while COEP did not. That issue was then merged into #4930 and there were some changes to "HTTPS state", but as far as I can tell there's nothing in the spec that checks for HTTPS for COEP currently.

Opening this issue per discussion with @annevk on IRC.

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic: cross-origin-embedder-policyIssues and ideas around the new "require CORP for subresource requests and frames and etc" proposal

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions