Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I could easily see making <script> and <link> resources required to be separately requested (like images are now -- ignoring data/base64 resources), but we're back to redefining HTML.

This has been implemented in HTTP (not HTML); you can enable the requirement right now by serving your pages with an appropriate Content-Security-Policy header.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: