Skip to content

Conversation

@hamishwillee
Copy link
Collaborator

FF142 adds support for specifying a style as a blocked destination (behind a preference) in https://bugzilla.mozilla.org/show_bug.cgi?id=1974247. This updates the docs to note that this is an allowed value for the Integrity-Policy and Integrity-Policy-Report-Only headers.

Related docs work can be tracked in #40667

@hamishwillee hamishwillee requested review from a team as code owners August 15, 2025 00:43
@hamishwillee hamishwillee requested review from chrisdavidmills and removed request for a team August 15, 2025 00:43
@github-actions github-actions bot added Content:HTTP HTTP docs Content:Security Security docs size/s [PR only] 6-50 LoC changed labels Aug 15, 2025
The HTTP **`Integrity-Policy-Report-Only`** response header allows website administrators to report on resources that the user agent loads that would violate [Subresource Integrity](/en-US/docs/Web/Security/Subresource_Integrity) guarantees if the integrity policy was enforced (using the {{HTTPHeader("Integrity-Policy")}} header).

Reports may be generated for requests on specified [request destinations](/en-US/docs/Web/API/Request/destination) that omit integrity metadata, or that are made in [no-cors](/en-US/docs/Web/API/Request/mode#no-cors) mode.
Reports may be generated for requests on specified [request destinations](#blocked-destinations) that omit integrity metadata, or that are made in [no-cors](/en-US/docs/Web/API/Request/mode#no-cors) mode.
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note, the link was good, but it is more useful here to be able to jump down to the field to find out what destinations are blocked. The old link appears there if people want to find out more about destinations.

@github-actions
Copy link
Contributor

github-actions bot commented Aug 15, 2025

Preview URLs

Flaws (3)

Note! 2 documents with no flaws that don't need to be listed. 🎉

URL: /en-US/docs/Web/HTTP/Reference/Headers/Integrity-Policy
Title: Integrity-Policy header
Flaw count: 3

  • unknown:
    • No generic content config found
    • no blog root
    • no blog root

(comment last updated: 2025-08-18 07:10:58)

@hamishwillee
Copy link
Collaborator Author

@chrisdavidmills As you know, I'm working tomorrow but then gone for a bit. If you don't look at this today and you think changes are required, can you just make them and merge. If you make the changes today I can still look at them in a timely manner.

@hamishwillee hamishwillee force-pushed the ff142_integrity_policy_style branch from c14fcf3 to 860e670 Compare August 17, 2025 23:26
Copy link
Contributor

@chrisdavidmills chrisdavidmills left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice one @hamishwillee. I did as you asked and fixed up a few small bits and bobs. Mostly fine though.

@chrisdavidmills chrisdavidmills merged commit 32f4ac9 into mdn:main Aug 18, 2025
8 checks passed
@hamishwillee hamishwillee deleted the ff142_integrity_policy_style branch August 18, 2025 08:08
@hamishwillee
Copy link
Collaborator Author

Thanks very much. Those fixes all look great.

estelle pushed a commit that referenced this pull request Aug 19, 2025
* FF142 Integrity-Policy can be enforced on scripts

* Fix a couple of instances of scripts only to scripts and stylesheets

* code font

* Couple of small fixes

---------

Co-authored-by: Chris Mills <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content:HTTP HTTP docs Content:Security Security docs size/s [PR only] 6-50 LoC changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants