Subresource integrity for images and other media?

Subresource's integrity seems to be an awesome stop second, allowing you to safely use third-party controlled HTTP resources.

However, the specification only considers interfaces HTMLLinkElementand HTMLScriptElement:

Note

In the future revision of this specification, it will likely include support for the integrity of all possible podresursov, ie a, audio, embed, iframe, img, link, object, script, source, trackand video.

I understand that the content referenced by the elements scriptand linkmore "active", but browsers remove the green lock to extract even relatively innocuous images via a simple HTTP, while the specification chooses to ignore them? This seems to be a huge lack of foresight for me.

What was the reason for this and when can we expect a “future revision”, if at all?

+4
source share
1 answer

SRI , , , . , JQuery CDN, , , ( - ). SRI .

, . JQuery http , , SRI.

, :

  • , (- SRI).
  • cookie ( Secure).
  • (snooper , ).

SRI . , , (, https).

, , , upgrade-insecure-requests ( , ).

+3

Source: https://habr.com/ru/post/1626085/


All Articles