Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh hey, and all your js is now on one origin so if you have an xss in your third-party blog software, you now have xss in your app!

Also, good luck writing a sane content-security-policy if you do this.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: