3 ms·
it wouldn't be such a big deal if accidentally poisoning it with JavaScript wasn't so dang dangerous 77 years since Von Neumann, and we're still stuck holding
by elitepleb 3y ago
it wouldn't be such a big deal if accidentally poisoning it with JavaScript wasn't so dang dangerous
77 years since Von Neumann, and we're still stuck holding our instructions in the data
- justin_oaks 3y agoGood point. If only there were a way to mark a section of HTML as "no scripting here". Inside that section all <script> tags would be ignored, all onclick and similar attributes would be ignored, etc. That said, even if that existed, there'd still probably be some dangers you'd have to be careful to avoid.
- yyyk 3y ago>If only there were a way to mark a section of HTML as "no scripting here" iframe sandbox with srcdoc? Not so elegant, but it works. [Alternatively, iframe to another document and use CSP header there to ban everything]