Re: CSP and innerHTML

We've been using a CSP policy inserted via a DOM meta tag after load time
to prevent XSS via innerHTML. It effectively makes all calls to innerHTML
equivalent to toStaticHTML

Received on Tuesday, 30 April 2013 18:59:28 UTC