AVTOKYO2014ã§ãã«ããããããã¨ãã£ããã«ãã¯ãããããã¨ããã¦ãããåã§Content-Security-Policyããã¼ãã«è©±ããã¦ãã¾ããã Future of Web Security Opened up by CSP from Muneaki Nishimura å
容ã¯ã¹ã©ã¤ãã®ã¨ããã§ãæ»æè
ã¯Fiddlerãªã©ã使ã£ã¦ä»»æã®CSPéåã¬ãã¼ãJSONãéä¿¡å¯è½ã§ãããã¨ãFirefoxã®å ´åã«ã¯CSPéåã¬ãã¼ãã®JSONå
ã«ã<ãã>ããªã©ãå«ã¾ããã®ã§ãéåã¬ãã¼ãã表示ãã管çç»é¢ã§ã®ã¨ã¹ã±ã¼ãæ¼ããããã¨éåã¬ãã¼ããéãã¦ç®¡çç»é¢å
ã§XSSããããªã©ã®è©±ãè¡ããå®éã«ç®¡çç»é¢ã§ã®XSSã®ãã¢ãè¡ãã¾ããã ãã¢ã¯ããã¾ãç´°ãããã¨ã¯èãã¦ãªãã£ããã§ãããã¢ããªãè¦æãªã«ãããããããããå³ãåºãã¦ã¦ã横ã§è¦ã¦ãã¦ã楽ããã£ãã§ããã¡ãªã¿ã«ç´åã®æã¡åã
{{#tags}}- {{label}}
{{/tags}}