
Loading…
Local mirroring breaking sites using CSP #384
Artefact2
commented
gorhill
commented
Interesting.
At first glance, it looks like local mirroring should not kick in for sites with a CSP header, and to assume by default that such header will break redirecting to a data: URI.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hi Raymond,
The local mirroring feature interferes with sites that use Content-Security-Policy headers. For example:
You can reproduce the issue here: https://o.smium.org/