WICG / signature-based-sri

Signature-based Resource Loading Restrictions
https://wicg.github.io/signature-based-sri/
Other
20 stars 2 forks source link

Not CDNs #7

Closed mnot closed 7 years ago

mnot commented 7 years ago

CDNs operate in a number of different ways, and the pattern that's being described here (site maintains control of HTML and offloads embedded content to CDN) is a very small subset of that.

Using the term like this is going to be confusing for folks who use CDNs in a different way, and the underlying concern is really third-party content (as you say, when "it's delivered from a server outside their control.")

CDNs don't generally operate in the way that's being described here.

mikewest commented 7 years ago

Ok. I think that's probably an artifact of my ignorance. The proposed refinement in language seems totally reasonable to me. :)