注記: URL は、いくつもの異なる方式や文脈下で利用され得る。 厳格な URL を生産する目的においては、 [RFC3986] [RFC3987] を考慮したいと望まれることもあろう。 Note: URLs can be used in numerous different manners, in many differing contexts. For the purpose of producing strict URLs one may wish to consider [ RFC3986] [RFC3987].

HTML 文脈の外にある URL を取り扱う方式には、 Web ブラウザと他のソフトウェアの間で注意すべき相違点があることに警戒すること。 既存の Web 内容を壊すような URL 処理は受容されないが、 URL 処理のある重要な部分は実装に依存するものと見なされるべきである(例: file: URL を構文解析するときや, [RFC3986] [RFC3987] において構文エラーになるような URL に対し演算するとき)。 As a word of caution, there are notable differences in the manner in which Web browsers and other software stacks outside the HTML context handle URLs. While no changes would be accepted to URL processing that would break existing Web content, some important parts of URL processing should therefore be considered as implementation-defined (e.g. parsing file: URLs or operating on URLs that would be syntax errors under the [RFC3986] [RFC3987] syntax). [WebIDL] Cameron McCormack. Web IDL Level 1. 08 March 2016. CR. URL: https://www.w3.org/TR/WebIDL-1/ [XMLHttpRequest] Anne van Kesteren; et al. XMLHttpRequest Level 1. 30 January 2014. WD. URL: https://www.w3.org/TR/XMLHttpRequest/ [CSS-IMAGES-3] CSS Image Values and Replaced Content Module Level 3 URL: https://www.w3.org/TR/css3-images/ [CSS-IMAGES-4] CSS Image Values and Replaced Content Module Level 4 URL: https://www.w3.org/TR/css4-images/ [CSS3-FONTS] John Daggett. CSS Fonts Module Level 3. 3 October 2013. CR. URL: https://www.w3.org/TR/css-fonts-3/ [CSS4-IMAGES] Elika Etemad; Tab Atkins Jr.. CSS Image Values and Replaced Content Module Level 4. 11 September 2012. WD. URL: https://www.w3.org/TR/css4-images/ [CSSOM] Simon Pieters; Glenn Adams. CSS Object Model (CSSOM). 5 December 2013. WD. URL: https://www.w3.org/TR/cssom/ [EVENTSOURCE] Ian Hickson. Server-Sent Events. 3 February 2015. REC. URL: https://www.w3.org/TR/eventsource/ [RFC2119] S. Bradner. Key words for use in RFCs to Indicate Requirement Levels. March 1997. Best Current Practice. URL: https://www.rfc-editor.org/rfc/rfc2119 [RFC3986] T. Berners-Lee; R. Fielding; L. Masinter. Uniform Resource Identifier (URI): Generic Syntax. January 2005. Internet Standard. URL: https://www.rfc-editor.org/rfc/rfc3986 [RFC5988] M. Nottingham. Web Linking. October 2010. Proposed Standard. URL: https://www.rfc-editor.org/rfc/rfc5988 [WEBSOCKETS] Ian Hickson. The WebSocket API. 20 September 2012. CR. URL: https://www.w3.org/TR/websockets/ [WORKERS] Ian Hickson. Web Workers. 1 May 2012. CR. URL: https://www.w3.org/TR/workers/ [XML11] Tim Bray; et al. Extensible Markup Language (XML) 1.1 (Second Edition). 16 August 2006. REC. URL: https://www.w3.org/TR/xml11/ [XSLT] James Clark. XSL Transformations (XSLT) Version 1.0. 16 November 1999. REC. URL: https://www.w3.org/TR/xslt ●●ref_informative [RFC6797] Jeff Hodges; Collin Jackson; Adam Barth. HTTP Strict Transport Security (HSTS). RFC. URL: https://www.rfc-editor.org/rfc/rfc6797 [UIREDRESS] Giorgio Maone; et al. User Interface Security Directives for Content Security Policy. WD. URL: https://www.w3.org/TR/UISecurity/ ●●trans_metadata

~THIS_PAGEは、 W3C により勧告として公開された Content Security Policy ( Level 2 )を日本語に翻訳したものです。 ~PUB ●●spec_metadata このバージョン https://www.w3.org/TR/2016/REC-CSP2-20161215/ 最新公表バージョン https://www.w3.org/TR/CSP2/ 公表履歴 https://www.w3.org/standards/history/CSP2/ 編集者草案 https://w3c.github.io/webappsec-csp/ 実装報告 https://w3c.github.io/webappsec/implementation_reports/CSP2_implementation_report.html/ フィードバック [email protected] with subject line “[CSP2] … message topic …” (archives) 課題追跡 GitHub 編集 Mike West (Google Inc.) Adam Barth (Google Inc.) Dan Veditz (Mozilla Corporation) 前任編集者 Brandon Sterne (formerly of Mozilla Corporation) 制作 Web Application Security Working Group 正誤表 上に挙げた “課題追跡” に記録されています。 各国語翻訳(規範的でない) 英語版のみがこの仕様の規範的バージョンです。

Content Security Policy Level 2