CSP Policy Directives

There are no references to mediastream: URIs anywhere in the CSP documentation or the getUserMedia documentation. But if you use them together, you need to allow them somehow!


Remote Verification API

As pointed out on twitter ( ), the Node.js example violates the security best practices set out in

Introduction to the JavaScript shell

JavaScript shells

