newsmode MarketNews
arrow_back К списку
rss_feedSimon Willison ·13.05.2026 open_in_newОригинал

CSP Allow-list Experiment

13th May 2026

An experiment that shows that you can load an app in a CSP-protected sandboxed iframe (see previous note) and have a custom fetch() that intercepts CSP errors and passes them up to the parent window... which can then prompt the user to add that domain to an allow-list and then refresh the page.

I built this one with GPT-5.5 xhigh running in the Codex desktop app.

Recent articles

This is a beat by Simon Willison, posted on 13th May 2026.

Monthly briefing

Sponsor me for $10/month and get a curated email digest of the month's most important LLM developments.

Pay me to send you less!