Once again: if your spec uses the phrase "active document", there's a good chance it's wrong. If it's then deriving some sort of security state from the "active document", it's probably wrong in the "now you have a security bug" sense.
-
-
Do you have an example?
2 replies 0 retweets 0 likes
Replying to @lastontheboat @dveditz
https://github.com/w3c/webappsec-csp/pull/358#issuecomment-435405253 … or https://github.com/w3c/payment-request/issues/361 … are the ones that were at the top of my history.
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.