evalã¨reportOnlyã«ã¤ãã¦è¿½è¨ãã¾ãã (2016/10/10) 2016/10/20 ä»æ§åã¯ä»¥ä¸ã®éãã«ãªãã¾ãããAnti-XSS Response-Time Uniqueness Requirement ã¾ãããããåã¯ãXSS-Protectionãããã§ã¯ãªããARTURãããã¨ãªã£ã¦ããã¾ãããã¾ãå¤æ´ãããå¯è½æ§ãããã¾ãã Googleã®èª¿æ»ã«ããã¨ãCSPã«ããXSSã®é²æ¢ã¯ç¾å®çã«ãããã¤ã®æ¬ é¥ã«ããXSSã®é²æ¢å¹æããªããã¨ã示ãã¦ãã¾ãã調æ»ã¯ãCSP Is Dead, Long Live CSP!ãã¨ãã¦ACMã®ã«ã³ãã¡ã¬ã³ã¹ã§çºè¡¨ããããã¼ãã¼ãé²è¦§ãããã¨ãã§ãã¾ãã 9æã«è¡ãããW3C TPAC 2016ã®WebAppSecã®ãã¼ãã£ã³ã°ã§è°è«ãããGoogleã®Mike Westæ°ããæ°ããXSS Protectionã¨ããä»æ§ãææ¡ããã¦
{{#tags}}- {{label}}
{{/tags}}