Hacker News new | ask | show | jobs
by merb 1990 days ago
well it depends an administrator of an org can actually inject javascript without intercepting the http response stream.