- <h2property="dcterms:issued"datatype="xsd:dateTime"content="2014-03-18T09:26:21.000Z"id="w3c-first-public-working-draft-18-march-2014"><abbrtitle="World Wide Web Consortium">W3C</abbr> First Public Working Draft <timeclass="dt-published"datetime="2014-03-18">18 March 2014</time></h2>
+ <h2property="dcterms:issued"datatype="xsd:dateTime"content="2014-03-18T09:32:37.000Z"id="w3c-first-public-working-draft-18-march-2014"><abbrtitle="World Wide Web Consortium">W3C</abbr> First Public Working Draft <timeclass="dt-published"datetime="2014-03-18">18 March 2014</time></h2>
- <p>The <code>NI-URL</code> rule is defined in <ahref="http://tools.ietf.org/html/rfc6920#section3">RFC6920, section 3, figure 4</a>.</p>
+ <p>The <code>NI-URL</code> rule is defined in <ahref="http://tools.ietf.org/html/rfc6920#section-3">RFC6920, section 3, figure 4</a>.</p>
<p>The <code>integrity</code> IDL attribute must <ahref="http://www.w3.org/TR/html5/infrastructure.html#reflect">reflect</a> the <code>integrity</code> content attribute.</p>
@@ -1235,7 +1235,7 @@ <h4 id="handling-integrity-violations" aria-level="3" role="heading"><span class
a fallback resource as specified for each relevant element. If the fallback
resource fails an integrity check, the user agent <emclass="rfc2119"title="MUST">MUST</em> refuse to render or
execute the resource, <em>and</em> <emclass="rfc2119"title="MUST">MUST</em> <ahref="http://www.w3.org/TR/CSP11/#dfn-report-a-violation">report a(nother)
-violation</a>. (See <ahref="#the-noncanonical-src-attribute">the <code>noncanonical-src</code>
+violation</a>. (See <ahref="#the-noncanonical-src-attribute-todo">the <code>noncanonical-src</code>
attribute</a> for a strawman of how that might look).</p></div>
<divclass="issue"><divclass="issue-title"aria-level="4"role="heading"id="h_issue_7"><span>Issue 7</span></div><pclass="">If the document’s integrity policy contains <code>require-for-all</code>, the user agent
<li>The integrity metadata uses a hash function with very strong uniqueness
characteristics: SHA-512 or better.</li>
<li>If a Content Security Policy is active in a context, the <code>script</code> or
-<code>link</code> element which triggered the resource’s fetch has a <ahref="http://w3c.github.io/webappsec/specs/content-security-policy/csp-specification.dev.html#valid-nonces">valid nonce</a>.</li>
+<code>link</code> element which triggered the resource’s fetch has a <ahref="http://w3c.github.io/webappsec/specs/content-security-policy/csp-specification.dev.html">valid nonce</a>.</li>
</ul>
<divclass="issue"><divclass="issue-title"aria-level="3"role="heading"id="h_issue_16"><span>Issue 16</span></div><pclass="">More ideas? Limiting to resources with wide-open CORS headers and strong
- <p>The <code>NI-URL</code> rule is defined in <ahref="http://tools.ietf.org/html/rfc6920#section3">RFC6920, section 3, figure 4</a>.</p>
+ <p>The <code>NI-URL</code> rule is defined in <ahref="http://tools.ietf.org/html/rfc6920#section-3">RFC6920, section 3, figure 4</a>.</p>
<p>The <code>integrity</code> IDL attribute must <ahref="http://www.w3.org/TR/html5/infrastructure.html#reflect">reflect</a> the <code>integrity</code> content attribute.</p>
<li>The integrity metadata uses a hash function with very strong uniqueness
characteristics: SHA-512 or better.</li>
<li>If a Content Security Policy is active in a context, the <code>script</code> or
-<code>link</code> element which triggered the resource’s fetch has a <ahref="http://w3c.github.io/webappsec/specs/content-security-policy/csp-specification.dev.html#valid-nonces">valid nonce</a>.</li>
+<code>link</code> element which triggered the resource’s fetch has a <ahref="http://w3c.github.io/webappsec/specs/content-security-policy/csp-specification.dev.html">valid nonce</a>.</li>
</ul>
<pclass="issue"data-number="16">More ideas? Limiting to resources with wide-open CORS headers and strong
0 comments on commit
2819f1a