Conversation

I didn't realize trusted-types: 'none' could be added to explicitly forbid creating Trusted Types policies. twitter.com/shhnjk/status/ Added it to the global policy for attestation.app and grapheneos.org in addition to baseline require-trusted-types-for 'script'.
Quote Tweet
The story about how we killed XSS from Edge internal pages 😎 microsoftedge.github.io/edgevr/posts/e
1
8