Re: [w3c/FileAPI] "Null"ing out the Origin of a BLOB (#74)

You pretty much need to do it after-the-fact, since blobs can come from many places. Although I suppose you could wrap such blobs by a more secure variant. I was thinking that CSP could maybe just sandbox for an entire origin, but not before we have origin-wide policies I suppose.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/FileAPI/issues/74#issuecomment-286988704

Received on Thursday, 16 March 2017 08:27:42 UTC