3 ms·
Look SRI up on this very page. Web pages can make requests to other origins (GET image, script, XHR, POST to iframe, XHR). CORS allows you to read the response
by throwaway41597 11y ago
Look SRI up on this very page.
Web pages can make requests to other origins (GET image, script, XHR, POST to iframe, XHR). CORS allows you to read the response. But what you're asking would probably be hard to transition the whole web to without too much spam and DOS'ing.
The sandboxing for an external script you want already is feasible with an iframe with a different origin.