TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Cross-Origin Read Blocking

42 点作者 dedalus将近 7 年前

3 条评论

arkadiyt将近 7 年前
If you&#x27;re interested in cross origin information leaks and defenses against them (including Cross Origin Read Blocking), I highly recommend this short 7 page summary by Artur Janc and Mike West from Google:<p><a href="https:&#x2F;&#x2F;www.arturjanc.com&#x2F;cross-origin-infoleaks.pdf" rel="nofollow">https:&#x2F;&#x2F;www.arturjanc.com&#x2F;cross-origin-infoleaks.pdf</a>
AntonyGarand将近 7 年前
Will we be able to report errors using the upcoming report-to header? I didn&#x27;t see a report mechanism listed, but like with hpkp and cors I would like those errors to.be reporteable
colemickens将近 7 年前
Does anyone have good additional links? I don&#x27;t understand the risk of delivering an HTML document to. script tag src?
评论 #17562284 未加载
评论 #17562366 未加载