You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
**Rationale:** Embedded contexts violate the single-request fetch model (§4.14), create side-channel requests, and expand the attack surface (tracking, clickjacking, mixed policy contexts).
119
119
120
-
**Operational guidance (non-normative):**
121
-
Servers **SHOULD** send a Content Security Policy to prevent third-party framing:
122
-
123
-
`Content-Security-Policy: frame-ancestors 'none'`
124
-
125
-
This header blocks other sites from framing SLIM pages, reducing clickjacking risk.
126
-
127
-
128
120
129
121
### 4.11 File Size — ADVISORY
130
122
No hard maximum size; authors are encouraged to adopt a “less is more” mindset.
@@ -155,7 +147,7 @@ Follow SLIM versioning guidance (e.g., SLIM v1.0) and update the meta tag accord
155
147
156
148
SLIM authors and operators **SHOULD** consider deploying a Content Security Policy that enforces SLIM restrictions at the browser level. An example of a maximally restrictive CSP is:
0 commit comments