You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Requests for SVG files should be allowed to include HTML-only headers: CSP, X-XSS-Protection, etc.
Details
The SVG spec is really advanced, and allows a great deal of complex behavior (and vulnerabilities; see the Tor Browser's rationale for disabling SVG when increasing the security level). Headers like Content-Security-Policy can impact how the browser handles an SVG.
This feature could be considered a partial fix to #3403.
The text was updated successfully, but these errors were encountered:
🚀 Feature request
Description
Requests for SVG files should be allowed to include HTML-only headers: CSP, X-XSS-Protection, etc.
Details
The SVG spec is really advanced, and allows a great deal of complex behavior (and vulnerabilities; see the Tor Browser's rationale for disabling SVG when increasing the security level). Headers like
Content-Security-Policy
can impact how the browser handles an SVG.This feature could be considered a partial fix to #3403.
The text was updated successfully, but these errors were encountered: