HTML imports: new XSS hole?

How big of a problem is it that we're making <link> as dangerous as
<script>? HTML imports can point to any origin which then will be able
to execute scripts with the authority of same-origin.


-- 
http://annevankesteren.nl/

Received on Monday, 2 June 2014 09:33:12 UTC