Closed benjamingr closed 2 years ago
Denying data: src seems like a decent policy to have (it might break some of the generative file download libs)
Cross origin realms are by definition out of Snow's scope. Snow aspires to protect only against same origin realms, as they are the only ones that it can run code within. It comes to allow the defender to defend its realm against attackers - cross origin realms can't access the defender's realm in the first place.
added a comment to the demo so this will be clear @benjamingr
https://github.com/LavaMoat/snow/commit/2391bf7ca85c13c86a4942d6a6d8751b6a88d324