Hacker News new | ask | show | jobs
by aegarbutt 2954 days ago
The CSP policy was 'self'. The problem is that all file:// URIs share an origin in Electron.

So, 'self' is ALL file:// URIs.