Open marcoscaceres opened 1 year ago
This issue seems to be about CSP, not CORS?
Ah whoops, yes. Acronym soups getting all mixed up in my head. Fixed the title and OP.
However, we need to clarify what this means in relation to, say, "img-src", for example... as models can load png/jpg textures.
I don't know the answer myself, but I guess we can look at the precedents from CSS and SVG.
Ah whoops, yes. Acronym soups getting all mixed up in my head. Fixed the title and OP.
Browser generally frown upon subresource fetches. The model element should fetch only 1 file and not reach out later for additional ones. SVG-as-a-image was changed to no longer allow fetches.
Need to clarify that 3D resources can fetch resources, and as such need to be subject the document's CSP (probably "media-src"). However, we need to clarify what this means in relation to, say, "img-src", for example... as models can load png/jpg textures.