Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Where possible, default to defining style and behaviour with inline HTML attributes

I'm not aware that an inline style, and particularly the inline JS in their example can be nonced to prevent script and style injection.

So no. I will not be following that part of the guideline. Not until the security aligns with reality.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: