ParentFull threadcoconutrandom·This will stop embedding it in <script> but why couldn't the attacking website do the same with eval and substring?View on HN