| ▲ | MarsIronPI 17 hours ago | |
Shouldn't the ignoring of scripting be done at the user agent level? Maybe some kind of HTTP header to allow sites to disable scripts in SVG ala CORS? | ||
| ▲ | antiloper 6 hours ago | parent [-] | |
Content-Security-Policy: default-src 'none' | ||