Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CSP does help, but it is document-specific, not js-context specific. At least in Chrome, tracing the js context that was responsible for some network request would be significantly more difficult to implement.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: