logoalt Hacker News

MarsIronPIlast Thursday at 11:06 PM2 repliesview on HN

Shouldn't the ignoring of scripting be done at the user agent level? Maybe some kind of HTTP header to allow sites to disable scripts in SVG ala CORS?


Replies

demurgostoday at 2:32 AM

It's definitely a possible solution if you control how the file are displayed. In my case I preferred the files to be safe regardless of the mechanism used to view them (less risk of misconfiguration).

antiloperyesterday at 10:10 AM

Content-Security-Policy: default-src 'none'