w3c / webappsec-suborigins

Suborigins
https://w3c.github.io/webappsec-suborigins/
Other
25 stars 9 forks source link

Tradeoff between unsafe-* and refactoring #76

Open annevk opened 6 years ago

annevk commented 6 years ago

@arthurjanc your comment in #74 made me curious why there's no "unsafe-cors", "unsafe-storage", etc. to opt into "physical origin" behavior for things you don't like to touch when enabling suborigins. How exactly is this boundary determined?