Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(611)

Issue 8103008: Add content-security-policy directive to chrome://hung-renderer. WebUI pages should specify CSP ... (Closed)

Created:
9 years, 2 months ago by Tom Sepez
Modified:
9 years, 2 months ago
CC:
chromium-reviews, arv (Not doing code reviews)
Visibility:
Public.

Description

Add content-security-policy directive to chrome://hung-renderer. WebUI pages should specify CSP as a second line of defense against XSS vulnerabilities. Committed: http://src.chromium.org/viewvc/chrome?view=rev&revision=103727

Patch Set 1 #

Patch Set 2 : '' #

Unified diffs Side-by-side diffs Delta from patch set Stats (+4 lines, -3 lines) Patch
M chrome/browser/browser_resources.grd View 1 chunk +1 line, -1 line 0 comments Download
M chrome/browser/resources/hung_renderer_dialog.html View 1 1 chunk +3 lines, -2 lines 0 comments Download

Messages

Total messages: 3 (0 generated)
Tom Sepez
Found another one that crept its way in ...
9 years, 2 months ago (2011-09-30 21:11:39 UTC) #1
abarth-chromium
LGTM. Can we switch this to a whitelist of pages that don't have the policy? ...
9 years, 2 months ago (2011-10-01 01:03:02 UTC) #2
Tom Sepez
9 years, 2 months ago (2011-10-03 16:45:36 UTC) #3
I'll file a bug for moving to the "real" header.  Tx.

Powered by Google App Engine
This is Rietveld 408576698