Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

…At the cost of having to add `img-src data:;` to your CSP, which is unsafe.

https://security.stackexchange.com/questions/94993/is-includ...



How is that unsafe exactly?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: