Hacker News new | past | comments | ask | show | jobs | submit login

External sources yes, preventing an app to inject inline HTML and JavaScript is tricky.



You can block all inline scripts via CSP.


That’s why I said tricky and not impossible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: