←back to thread

1597 points seapunk | 2 comments | | HN request time: 0.001s | source
1. chias ◴[] No.22706088[source]
I thought this was going to be about their hilarious CSP, which whitelists the following domains:

    'unsafe-eval'
    'unsafe-inline'
    blob:
    https://*.50million.club
    https://*.adroll.com
    https://*.cloudfront.net
    https://*.google.com
    https://*.hotjar.com
    https://*.zoom.us
    https://*.zoomus.cn
    https://*.zopim.com
    https://ad.lkqd.net
    https://ajax.aspnetcdn.com
    https://apiurl.org
    https://appsforoffice.microsoft.com
    https://assets.zendesk.com
    https://bat.bing.com
    https://cdn.5bong.com
    https://cdn.jsdelivr.net
    https://cdncache-a.akamaihd.net
    https://code.jquery.com
    https://connect.facebook.net
    https://consent.trustarc.com
    https://extnetcool.com
    https://fp166.digitaloptout.com
    https://googleads.g.doubleclick.net
    https://intljs.rmtag.com
    https://pi.pardot.com
    https://px.ads.linkedin.com
    https://ruanshi2.8686c.com
    https://rum-static.pingdom.net
    https://s.dcbap.com
    https://s.yimg.com
    https://s.ytimg.com
    https://s3.amazonaws.com
    https://scout-cdn.salesloft.com
    https://sealserver.trustwave.com
    https://secure-cdn.mplxtms.com
    https://secure.myshopcouponmac.com
    https://snap.licdn.com
    https://sp.analytics.yahoo.com
    https://srvvtrk.com
    https://static.zdassets.com
    https://static2.sharepointonline.com
    https://tag.demandbase.com
    https://tpc.googlesyndication.com
    https://tracking.g2crowd.com
    https://translate.googleapis.com
    https://trk.techtarget.com
    https://unpkg.com
    https://www.comeet.co
    https://www.dropbox.com
    https://www.google-analytics.com
    https://www.googleadservices.com
    https://www.googletagmanager.com
    https://www.gstatic.com
    https://www.youtube.com
    https://d.adroll.mgr.consensu.org
    https://serve2.cheqzone.com
    https://static.ada.support
    'self'
via: https://twitter.com/jasvir/status/1242518507683639296
replies(1): >>22706721 #
2. quickthrower2 ◴[] No.22706721[source]
Yes unpkg and s3, anyone can get content up on them.