Re: [whatwg/fetch] Reverse HTTP for CSRF/XSS-proofing of localhost webservers (Issue #1685)

this prevents further connections without preflight: https://wicg.github.io/private-network-access/#csp

but it doesn't make a fully isolated sandbox. you can still accept requests from public websites.

(we do appreciate that it blocks navigation by default tho. that's really nice to see.)

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1685#issuecomment-1636191892
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1685/1636191892@github.com>

Received on Friday, 14 July 2023 17:52:53 UTC