Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
kccqzy
36 days ago
|
parent
|
context
|
favorite
| on:
Goodbye InnerHTML, Hello SetHTML: Stronger XSS Pro...
If you just serve SVGs through <img> tag it’ll be much safer. I never understood the appeal of inline <svg> anyways.
lenkite
36 days ago
|
next
[–]
Inline SVG is stylable with CSS styles in the same HTML page.
runarberg
36 days ago
|
parent
|
next
[–]
Also animatible with the same context (Animation API, etc.) as the parent page, so different SVGs can influence each other’s animations.
rwj
36 days ago
|
prev
[–]
Inline reduces round trips.
toast0
36 days ago
|
parent
[–]
You can use img with a data url?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: