Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Retr0id
on Nov 24, 2024
|
parent
|
context
|
favorite
| on:
This website is hosted on Bluesky
The CSP headers didn't used to be there, which I used to pop an alert(), way back. (at the time there was also a MIME whitelist, but that whitelist included image/svg+xml, which allows script execution)
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: