Quantcast
Channel: User Chris - Stack Overflow
Viewing all articles
Browse latest Browse all 42

Comment by Chris on Content-Security-Policy (CSP): how to allow svg image in object

$
0
0
It should be noted that this opens the page up for an attack vector for any item on the page using object-src data. If your goal is security you'd be better off using a sha hash of the script trying to be executed rather than opening up this hole.

Viewing all articles
Browse latest Browse all 42

Trending Articles