|
|
|
|
|
by mtlynch
1029 days ago
|
|
>I know XSS is dying due to CORS CORS isn't related to XSS. CORS actually isn't a security protection at all. It's a way for web apps to explicitly disable standard protections that browsers apply to enforce same origin policy. You might be thinking of Content Security Policy (CSP).[0] That's the most effective protection I'm aware of for XSS, but it's not very widely used because so few JavaScript libraries are compatible with it. [0] https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP |
|
>so few JavaScript libraries are compatible with it.
is this because of the 'eval' function specifically, or is there other reasons?