http - Would setting script-src 'self' and frame-src 'unsafe-inline' conflict with each other? -


if have content-security-policy looks this:

default-src 'self' script-src 'self' frame-src 'unsafe-inline' 

and have web page has frame inside it, frame points external source. frame runs script comes same origin else in frame.

i don't understand how these interact each other. script , frame settings conflict each other in way, or case of frame-src allowed run script?

you can set 'unsafe-inline' in default-src, script-src or style-src directives in csp. not valid in frame-src, or child-src frame-src deprecated.

when loading frame can't set csp restrictions on honour it's own csp set host if present.


Comments

Popular posts from this blog

jOOQ update returning clause with Oracle -

java - Warning equals/hashCode on @Data annotation lombok with inheritance -

java - BasicPathUsageException: Cannot join to attribute of basic type -