Forum Moderators: open

Message Too Old, No Replies

Gmail gets CSP support to stop extensions from loading

         

bill

10:25 pm on Dec 16, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



http://venturebeat.com/2014/12/16/gmail-gets-content-security-policy-support-to-stop-extensions-from-loading-unsafe-code/ [venturebeat.com]

Gmail gets Content Security Policy support to stop extensions from loading unsafe code

Google today added [gmailblog.blogspot.jp] support for Content Security Policy (CSP) to Gmail. The security feature protects users by stopping extensions from loading unsafe code.

CSP is a computer security concept for preventing cross-site scripting (XSS) and related attacks. It provides a standard HTTP header that allows website owners to declare approved sources of content that browsers should be allowed to load on a given page (such as JavaScript, CSS, HTML frames, fonts, images, and even embeddable objects like Java applets, ActiveX, audio, and video files).