Page MenuHomePhabricator

Block use of "<base />" in the Content Security Policy
ClosedPublic

Authored by epriestley on Mar 1 2018, 2:54 AM.
Tags
None
Referenced Files
F15473654: D19158.diff
Sun, Apr 6, 12:29 AM
F15460228: D19158.id45894.diff
Mon, Mar 31, 9:10 PM
F15458933: D19158.id45893.diff
Mon, Mar 31, 8:25 AM
F15457335: D19158.id.diff
Sun, Mar 30, 3:45 PM
F15452639: D19158.diff
Sat, Mar 29, 6:25 AM
F15437714: D19158.diff
Tue, Mar 25, 9:08 PM
F15389000: D19158.diff
Mar 15 2025, 4:48 AM
F15385356: D19158.id45894.diff
Mar 14 2025, 10:20 PM
Subscribers
None

Details

Summary

Ref T4340. We don't use "<base />" so we can safely block it.

Test Plan

Injected "<base />" into a page, saw an error in the console showing that the browser had blocked it.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision was not accepted when it landed; it landed in state Needs Review.Mar 1 2018, 2:55 AM
epriestley requested review of this revision.
This revision was automatically updated to reflect the committed changes.