A photo of Phil Hawksworth's face
Phil Hawksworth @philhawksworth replying to this from @sunnysinghio
@sunnysinghio @cloudinary Luckily you can give @cloudinary a list of domains which are approved asset sources, so you can safeguard against that.

To test, try specifying a resource from another domain in this:
https://res.cloudinary.com/philhawksworth/image/fetch/q_auto,f_auto,h_200/https://petsof.netlify.app/images/angel.jpg

My tweets and posts live here on my own domain these days.
You can explore them here and follow me on Mastodon instead of Twitter where I'm not currently active.