Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[HTTP header] Cross-Origin-Resource-Policy #4355

Closed
Malvoz opened this issue Jul 3, 2018 · 2 comments
Closed

[HTTP header] Cross-Origin-Resource-Policy #4355

Malvoz opened this issue Jul 3, 2018 · 2 comments

Comments

@Malvoz
Copy link
Contributor

Malvoz commented Jul 3, 2018

The Cross-Origin-Resource-Policy (CORP) header enables authors to prevent other domains from loading resources by restricting any kind of cross-origin load to protect themselves against Spectre attacks (essentially a standardized method of hotlink protection).

Available in Safari 12.

Tracking bugs:

Note, this header was initially proposed as From-Origin, can include it in keywords for developers to find the latest version.

@Malvoz
Copy link
Contributor Author

Malvoz commented Apr 16, 2019

We should note the bug in Chrome 73 with regards to downloads of resources that include this header in the response: https://bugs.chromium.org/p/chromium/issues/detail?id=952834

@Fyrd
Copy link
Owner

Fyrd commented May 23, 2020

@Fyrd Fyrd closed this as completed May 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants