5 ms·
Couldn't Content Security Policy (CSP) [1] be used to mitigate this attack? [1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP https://developer.mozill
by wuyishan 9y ago
Couldn't Content Security Policy (CSP) [1] be used to mitigate this attack?
[1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
- maxchehab 9y agoIt actually can't. Instagram does use this protect java-script injection from extensions, but clearly injecting CSS is allowed.