• #dev 2018-07-14
  • Prev
    Next
  • #indieweb
  • #dev
  • #wordpress
  • #meta
  • #stream
  • #microformats
  • #known
  • #events
#dev ≡
  • ←
  • →
2018-07-14 UTC
# 20:23
Zegnat
You could have something like `Content-Security-Policy: default-src 'self'; script-src 'none'`. So you, by default, only allow assets to load from your own domain (self), and do not allow scripts at all.