ããã«ã¡ã¯ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®koboã§ãããã¯ã·ãã«ã¯2018å¹´4æã«å ¥ç¤¾ãã¦ãããã»ãã¥ãªãã£è¦³ç¹ã§ã®ã¢ããªã±ã¼ã·ã§ã³éçºãèå¼±æ§å ±å¥¨éå¶åº¦ã®éç¨ãªã©ãè¡ã£ã¦ãã¾ãã æ¬è¨äºã§ã¯ãç¾å¨ãã¯ã·ãã®ä¸é¨ã®ãµã¼ãã¹ã§åãçµãã§ããContent Security Policyã«ã¤ãã¦ç¥è¦ãå ±æãã¾ãã æ¦è¦ Content Security Policy (CSP) ã¯ãXSSã主ã¨ããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ã®åé¡ã軽æ¸ããããã«èæ¡ããããã©ã¦ã¶ã®ã»ãã¥ãªãã£æ©æ§ã§ãã ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã¯ã Content-Security-Policy ããããHTTPã¬ã¹ãã³ã¹ã«å«ãããã¨ã§ãæå³ãã¦ããªãJavaScriptã®å®è¡ããªã½ã¼ã¹ã®èªã¿è¾¼ã¿ããã©ã¦ã¶å´ã§å¶éãããã¨ãã§ãã¾ãã CSPã¯2012å¹´é ãããã©ã¦ã¶ã«å®è£ ããã¦ãã¾ããã2016å¹´ã®Googleã®èª¿æ»ã«ã
{{#tags}}- {{label}}
{{/tags}}