4 ms·
AMP documents are delivered with a Content-Security-Policy which instructs the browser not to load javascript resources outside the AMP origin, including inline
by gregable 7y ago
AMP documents are delivered with a Content-Security-Policy which instructs the browser not to load javascript resources outside the AMP origin, including inline scripts. The AMP Cache ensures no remote images or other remote resources can be loaded in preload.
When using signed exchanges, the preload does not even parse the document until navigation, as per the signed exchange spec.
Analytics loading is deferred until after user navigation, which makes sense as the user has yet to navigate to the document.
The AMP Cache serves publicly cached HTML documents, and the static fonts/images within those documents. If a document wants to render user specific data, it can load that directly from the publisher's origin upon navigation (not routed via the AMP Cache). See, for example https://amp.dev/documentation/components/amp-list/ https://amp.dev/documentation/components/amp-list/. Analytics, ads, etc are all fetched directly from the vendor or publisher origin and the AMP Cache will neither proxy nor otherwise see this data.