-
Gary Wong authored
The old approach included the manifests directly in the HTML, which caused two problems: (1) any manifest XML element that isn't valid HTML could get modified by the browswer; (2) a malicious user could insert arbitrary HTML to be executed by an admin's browsers when visiting the user's manifest.
86602b53