-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
The current CSP sandbox is based on my understanding of the CSP spec, but we know I missed some that could have allowed for bypasses, etiher because of inheritances or different type of sources. Would be nice if we modeled the CSP spec in something like z3, then my validating function, and then we solved to look for javascript/css/objects execution vectors.
Metadata
Metadata
Assignees
Labels
No labels