4 ms·
The request will be blocked by the CSP.
by gildas 2y ago
The request will be blocked by the CSP.
- Thorrez 2y agoWhy? The CSP policy isn't setting default-src or img-src. So image loads are allowed from everywhere.
- gildas 2y agoThat was just an example of syntax, nothing prevents you from blocking more resources and sandbox the page.
- Thorrez 2y agoIf we make it strict enough to block exfiltration, it'll block the external libraries from loading. So that means we have to load our scripts from the same origin instead of external origins (as jclarkcom suggested). But the whole reason for CSP was to allow us to use external libraries without exfiltration risk. If we stop using external libraries, then our motivation for using CSP is gone. So CSP is useless for the purpose of this conversation.
- gildas 2y agoI think there's been a misunderstanding, there was an error in the article suggesting that zip.min.js is not inlined in the page. This error has been corrected meanwhile. I'm sorry for that. The goal is obviously to create pages that work offline, as shown in the demo.