Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

you could just add a new public=true option to counter this. I think you can even already check that with an iframe (or js head inject & timing) anyway, no need for CSP for that.


Or require crossorigin="anonymous", maybe in combination with Cache-Control: public.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: