6 ms·
hah, I forgot about that note. Good point - our stance was to protect from targeted code injections (by a coerced or hacked Google). But of course you're right
by malgorithms 11y ago
hah, I forgot about that note.
Good point - our stance was to protect from targeted code injections (by a coerced or hacked Google). But of course you're right, there's no point letting Google know at all.
I've made an issue to move font/css hosting off Google.
- chinathrow 11y agoThank you very much - great reaction.
- brandon 11y agoYou might also consider setting Content-Security-Policy headers to enforce your intent. http://content-security-policy.com/ http://content-security-policy.com/