Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems likely to have issues with most "Content-Security-Policy" rules because of the inline script in "onload" and the iframe. Makes it a non starter in real world production environments.


Can be imho solved with nonce or hash based policy


But isnt it the same exact domain?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: