Hacker News new | past | comments | ask | show | jobs | submit login

A good Content Security Policy [1] could prevent this as well as nullify the impact. If you're embedding a PDF in your app, you really should have one set up.

[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: