so if you use my browser (inlay.at) there’s no XSS unless i shipped it in the design systems i actually implement inside of its codebase. like within its built-in html tags third party server code has no power to inject any client code that isn’t already in the browser. my ds won’t allow script

0

If you have a fediverse account, you can quote this note from your own instance. Search https://bsky.brid.gy/convert/ap/at://did:plc:fpruhuo22xkm5o7ttr2ktxdo/app.bsky.feed.post/3mdk3q7g34k23 on your instance and quote it. (Note that quoting is not supported in Mastodon.)