HomePhorge

Block use of "<base />" in the Content Security Policy

Description

Block use of "<base />" in the Content Security Policy

Summary: Ref T4340. We don't use "<base />" so we can safely block it.

Test Plan: Injected "<base />" into a page, saw an error in the console showing that the browser had blocked it.

Maniphest Tasks: T4340

Differential Revision: https://secure.phabricator.com/D19158

Details

Provenance
epriestleyAuthored on Feb 28 2018, 6:51 PM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rPa2fdf14275f9: Stop using forms to download files in file embed and lightbox elements
Branches
Unknown
Tags
Unknown

Event Timeline