Please use the Apache issue tracking system for new NetBeans issues (https://issues.apache.org/jira/projects/NETBEANS0/issues) !!
Bug 267853 - Support Integrity attribute on link and script tags
Support Integrity attribute on link and script tags
Status: NEW
Product: web
Classification: Unclassified
Component: HTML Editor
8.2
PC Linux
: P3 with 7 votes (vote)
: TBD
Assigned To: Milutin Kristofic
issues@javaee
:
: 269580 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-09-04 08:15 UTC by Jenselme
Modified: 2018-01-22 09:46 UTC (History)
3 users (show)

See Also:
Issue Type: DEFECT
:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jenselme 2016-09-04 08:15:02 UTC
For instance if you copy the code to use bootstrap CDN from http://getbootstrap.com/getting-started/#download-cdn, you'll get warnings saying that integrity attribute is not allowed at this point for script and link tag. However, this new attribute is valid: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity

<!-- Latest compiled and minified CSS -->
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css" integrity="sha384-BVYiiSIFeK1dGmJRAkycuHAHRg32OmUcww7on3RYdg4Va+PmSTsz/K68vbdEjh4u" crossorigin="anonymous">

<!-- Optional theme -->
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap-theme.min.css" integrity="sha384-rHyoN1iRsVXV4nD0JutlnGaslCJuC7uwjduW9SVrLvRYooPp2bWYgmgJQIXwl/Sp" crossorigin="anonymous">

<!-- Latest compiled and minified JavaScript -->
<script src="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.js" integrity="sha384-Tc5IQib027qvyjSMfHjOMaLkfuWVxZxUPnCJA7l2mCWNIpG9mGCD8wGNIcPD7Txa" crossorigin="anonymous"></script>

NetBeans should report the tag as valid. What would also be nice is to use the value from the integrity attribute and display a warning if the file doesn't match the provided hash.
Comment 1 jochemb 2017-01-25 20:10:03 UTC
*** Bug 269580 has been marked as a duplicate of this bug. ***


By use of this website, you agree to the NetBeans Policies and Terms of Use. © 2014, Oracle Corporation and/or its affiliates. Sponsored by Oracle logo