3 ms·
But https doesn't 'let you know for sure that the content is exactly what the owner of the site intended' as it doesn't protect you from xss
by dukky 11y ago
But https doesn't 'let you know for sure that the content is exactly what the owner of the site intended' as it doesn't protect you from xss
- abraham 11y agoThan you fix the XSS vulnerabilities and implement CSP. Shitty security practices is not an excuse for more shitty security practices. https://developer.mozilla.org/en-US/docs/Web/Security/CSP https://developer.mozilla.org/en-US/docs/Web/Security/CSP