3 ms·
What a nice useful easy-to-use service, thanks for this, Jonai :) A comment (relevant to this site but also a more general ramble towards the direction of "why
by wfn 8y ago
What a nice useful easy-to-use service, thanks for this, Jonai :)
A comment (relevant to this site but also a more general ramble towards the direction of "why don't sites which use production-important JS try this more often"): given that the default non-API use case involves users running client-side JS, I wonder if you've considered pinning your "must send only the hash to the server" script code via CSP / script-src: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/script-src https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
(When JS scripts are "stable" enough, compute their hashes and include those hashes in the source via script-src (a sort of "certificate pinning" thing). I know it's not supported everywhere yet etc etc, I haven't paid close attention re: this but maybe that's the reason as to its limited adoption thus far?..)
Anyway, very smooth and I love the "can prove if service is gone" and "no stupid ICO" parts, obviously.
- flixic 8y agoThanks for the comment, Kostai! The entire frontend is a static Vue.js thing built with Vue CLI that uses Webpack behind the scenes. It seems I should be able to automatically add CSP via a webpack plugin. Noted.