| ▲ | johncolanduoni a year ago | |||||||
`sandbox` doesn’t affect making requests via HTML (images, stylesheets, etc.). | ||||||||
| ▲ | nightpool a year ago | parent | next [-] | |||||||
Right, but what would be the security impact of that compared to just plain HTML? I guess it allows for some form of view counting or IP exfiltration, but other than that anything you can do with an external request you could do with an embedded data URI. | ||||||||
| ||||||||
| ▲ | a year ago | parent | prev [-] | |||||||
| [deleted] | ||||||||