Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"The script doesn't run unless the file is directly opened (you can't run scripts from (<img src="/image.svg">)."


It will run if its in an <object> tag.


So if you're directly embedding the thing. This is a somewhat rare use case, should not be banned almost anywhere...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: