Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> if someone manages to inject arbitrary HTML

If they can, why wouldn’t it be inline <script>?



Because CSP can be configured to block inline scripts.


The syntax to allow inline scripts is even "unsafe-inline" to emphasize that you are entering the danger zone.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: