Why Nostr? What is Njump?
2023-05-26 06:20:54
in reply to

bajax on Nostr: grumbulon (⁠◠⁠‿⁠・⁠)⁠—⁠☆ ​ God's Silliest Soldier wafu ...

It looks like it might be a good idea to implement CSPs. We can apparently whitelist all the scripts we want to allow the browser to run on the page. It would be something like:

Content-Security-Policy: script-src : https://domain/static/*.js

This would prevent any scripts from anywhere except /static directory from running regardless of any magic fuckery.
Author Public Key
npub16rws74jzn42yjxw0jzm6pt9xqrdfjat6uge5atg2035w830n8v5sgnd9ze