-
Notifications
You must be signed in to change notification settings - Fork 174
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Content security policy clean #1565
Content security policy clean #1565
Conversation
…rkus/luigi into 1449-content-security-policy-clean
Seems to work fine for solving the "unsafe-eval" csp issue. It seems like it doesn't solve the 'unsafe-inline' issue. That would mean we have to link this PR to the unsafe-eval issue instead and continue and work on the unsafe-inline one afterwards. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍
Resolves #1458
We accepted unsafe-inline for style-src as a potential risk, since we rely on some inline styles for configurable sizes like modals.