Skip to content

Remove redundant TrustedScript data checks from CSP algorithm - #818

Merged
antosart merged 1 commit into
w3c:mainfrom
Lochipi:remove-redundant-trusted-types-checks
Aug 13, 2026
Merged

antosart merged 1 commit into
w3c:mainfrom
Lochipi:remove-redundant-trusted-types-checks

Conversation

@Lochipi

@Lochipi Lochipi commented Aug 3, 2026 •

Copy link
Copy Markdown
Member

HostGetCodeForEval extracts the internal [[Data]] from TrustedScript
objects before HostEnsureCanCompileStrings invokes the CSP algorithm.
So, by the time EnsureCSPDoesNotBlockStringCompilation receives bodyArg
and parameterArgs, they are already plain strings.

These checks are now redundant since the comparison of
parameterStrings[index] and bodyString against the TrustedScript
objects' data, and the verification that arguments implement
TrustedScript, are already done by HostGetCodeForEval.

see:
https://html.spec.whatwg.org/#hostgetcodeforeval(argument)
https://html.spec.whatwg.org/#hostensurecancompilestrings(realm,-parameterstrings,-bodystring,-codestring,-compilationtype,-parameterargs,-bodyarg)
https://www.w3.org/TR/CSP3/#can-compile-strings


Preview | Diff

@Lochipi

Lochipi commented Aug 3, 2026

Copy link
Copy Markdown
Member Author

I'm a student in Igalia's Coding Experience program. Igalia is a W3C member. Can you help with the IPR check?

Comment thread index.bs Outdated
Comment thread index.bs Outdated

@nicolo-ribaudo nicolo-ribaudo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The spec change looks correct, other than some minor style comments. I'll see what to do about the IPR check.

Comment thread index.bs
Comment thread index.bs
@Lochipi
Lochipi force-pushed the remove-redundant-trusted-types-checks branch from 757fa8c to 47011be Compare August 3, 2026 18:40
@Lochipi

Lochipi commented Aug 3, 2026

Copy link
Copy Markdown
Member Author

thanks for the review @antosart @nicolo-ribaudo
the suggested changes are applied. If there's anything I'm still missing, I'll get to it asap.

@antosart
antosart requested a review from lukewarlow August 6, 2026 11:38
@antosart

antosart commented Aug 6, 2026

Copy link
Copy Markdown
Member

@lukewarlow would you mind doublechecking this?

Comment thread index.bs Outdated

@lukewarlow lukewarlow left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bar the two fixes I mentioned, this LGTM thanks for doing this!

Comment thread index.bs Outdated

@mikewest mikewest left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, modulo @lukewarlow's comments which seem accurate to me.

@Lochipi
Lochipi force-pushed the remove-redundant-trusted-types-checks branch from 47011be to 3731c15 Compare August 7, 2026 15:59
@nicolo-ribaudo

Copy link
Copy Markdown
Member

This should be ready now? :)

@antosart

Copy link
Copy Markdown
Member

This should be ready now? :)

Indeed. Thanks for the ping!

@antosart
antosart merged commit e81d712 into w3c:main Aug 13, 2026
2 checks passed
github-actions Bot added a commit that referenced this pull request Aug 13, 2026
SHA: e81d712
Reason: push, by antosart

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants