Always provide documents a ContentSecurityPolicy
Currently, for some non-attached Documents, we skip providing CSP. There doesn't seem to be any specific reason for this, or pattern for when we do or don't provide it. This has the added benefit of fixing a corner case where we can end up inspecting a CSP that was not completely initialized. Bug: 1067034 Test: http/tests/security/contentSecurityPolicy/csp-violation-in-detached-document.html Change-Id: Ic8f30cc24469618b967f1c8325f7cf144b8cb876 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2209621 Commit-Queue: Nate Chapin <japhet@chromium.org> Reviewed-by:Kentaro Hara <haraken@chromium.org> Cr-Commit-Position: refs/heads/master@{#772317}
Showing
Please register or sign in to comment