Global Information Lookup Global Information

Subresource Integrity information


Subresource Integrity or SRI is a W3C recommendation to provide a method to protect website delivery. Specifically, it validates assets served by a third party, such as a content delivery network (CDN). This ensures these assets have not been compromised for hostile purposes.

To use SRI, a website author wishing to include a resource from a third party can specify a cryptographic hash of the resource in addition to the location of the resource. Browsers fetching the resource can then compare the hash provided by the website author with the hash computed from the resource. If the hashes don't match, the resource is discarded.[1]

A sample script element with integrity and crossorigin attribute used by the SRI:

<script src="https://cdn.example.com/app.js"
         integrity="sha384-+/M6kredJcxdsqkczBUjMLvqyHb1K/JThDXWsBVxMEeZHEaMKEOEct339VItX1zB"
         crossorigin="anonymous"></script>
  1. ^ "Subresource Integrity". Mozilla Developer Network. Retrieved 14 April 2016.

and 6 Related for: Subresource Integrity information

Request time (Page generated in 0.7825 seconds.)

Subresource Integrity

Last Update:

Subresource Integrity or SRI is a W3C recommendation to provide a method to protect website delivery. Specifically, it validates assets served by a third...

Word Count : 154

Content delivery network

Last Update:

targeted as a way to inject malicious content into pages using them. Subresource Integrity mechanism was created in response to ensure that the page loads...

Word Count : 4294

Content Security Policy

Last Update:

standards are being proposed by W3C, most of them complementary to CSP: Subresource Integrity (SRI), to ensure only known, trusted resource files (typically JavaScript...

Word Count : 1780

Web skimming

Last Update:

data is then submitted to a server under control of the attacker. Subresource Integrity or a Content Security Policy can be used to protect against formjacking...

Word Count : 610

SRI

Last Update:

vehicles Sri Lanka, IOC country code Smart Readiness Indicator Subresource Integrity of a website Sumitomo Rubber Industries, a global tire and rubber...

Word Count : 309

BrowseAloud

Last Update:

Both Helme and the NCSC recommended that website developers use subresource integrity as a defence against such attacks. The attack was estimated to have...

Word Count : 907

PDF Search Engine © AllGlobal.net