https://github.com/berthubert/trifecta/blob/main/README.md#k... has a list. The most painful one for me is that I did not know .svg files can contain javascript that gets executed in the site context if you can get someone to click on a link to your .svg file!
ahubert|1 year ago
softsound|1 year ago
yread|1 year ago
Anyone tried using the new csp alpine.js build?
https://laravel-news.com/alpinejs-csp