4 ms·
How does this compare to HTMX (security wise)?
by max_ 1y ago
How does this compare to HTMX (security wise)?
- sudodevnull 1y agoSame, you control your signals and fragments. So you are responsible for proper escaping and thoughtful design.
- j13n 1y agoYou can disable all use of eval with htmx. The tradeoff is one has to write a bit more JavaScript. https://news.ycombinator.com/item?id=43650921 https://news.ycombinator.com/item?id=43650921
- sudodevnull 1y agoI have thoughts about a fully compliant CSP middleware, problem is it's per language so I'd probably only make for Go (maybe PHP & TS)
- geoka9 1y agoHashes or nonces?
- sudodevnull 1y agoHashed script content
- geoka9 1y agoThank you for doing this. Is it possible to follow the work somewhere?
- sudodevnull 1y agoNot right now. CSP in a Datastar context is mostly a red herring. If an enterprise wants it to check a box then please reach out.
- geoka9 1y agoI don't represent an enterprise; just a dev. It would make it easier to sell the idea of Datastar to clients if it was compatible with strict CSP.