Integrate with speculation rules #776
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This upstreams the monkeypatches from https://wicg.github.io/nav-speculation/speculation-rules.html#content-security-policy. At a high level, the additions are:
A new directive,
inline-speculation-rules
, which can be used if developers want to block inline JavaScript<script>
s but allow inline<script type=speculationrules>
s. This is done by introducing a new script type,script speculationrules
, to sit alongside the existingscript
andscript attribute
types; HTML passes this new value in.Handling of the new
"speculationrules"
request destination, which is used by theSpeculation-Rules
HTTP header. It cannot be blocked by CSP.This should be merged a bit after whatwg/html#11426. Otherwise it will reference the WICG draft.
Preview | Diff