Hacker News new | ask | show | jobs
by aortega 2967 days ago
You are correct, there's also a flaw on CSP not limiting all the ways you can download a resource. And at this time, it's still not fixed. We'll publish an advisory soon.