maybe an html meta tag that blocks all XMLHTTPRequests until the user consents. i don't think it would even matter if it was browser-specific
maybe an html meta tag that blocks all XMLHTTPRequests until the user consents. i don't think it would even matter if it was browser-specific
Of course that being said the policy would basically have to be "disable network" at a trigger point not just uploads as you can just as easily leak large amounts of data via triggering GETs by making img placeholders come into view or other equally tricky things that can't be distinguished from "app is just still loading".
For example...
1. Cross origin hyperlinks would have to be completely disabled 2. Same-origin URLs would need all url information (query params, path, etc) to remain completely client-side. The only thing transmitted to the server would be the base domain.
It's interesting to think about, at least.
Surely, though, a blocked network request never reaches the server and so it can't be used a 'flag'?