Skip to content

Get rid of inline CSS and remove unsafe-inline gradually from controllers #1127

Description

@LukasReschke
No description provided.

Activity

  1. rullzer commented on Sep 4, 2016

    @rullzer
    Member

    So probabaly a good step would be to create a stricter CSP which Apps can then start to use already.

    Then we could also start logging warnings on the old CSP.

  2. sunny75016 commented on Apr 28, 2020

    @sunny75016

    Open almost 4 years. Grateful if the NC cloud can works towards a solution.

  3. LukasReschke commented on Apr 28, 2020

    @LukasReschke
    MemberAuthor

    @sunny75016 I am sure Pull Requests are appreciated :-)

  4. sunny75016 commented on Apr 29, 2020

    @sunny75016

    In this thread someone suggested creating a strict CSP. There is my humble suggestion to keep the CSP short. If we replace default-src with 'none', then it becomes too long.

    Apache2:
    Header set Content-Security-Policy "default-src 'self'; img-src data: 'self'; upgrade-insecure-requests;"

    I am not using nginx so someone else can write its equivalent. I hope the suggestion is useful to authors who want to get rid of 'unsafe-inline' from script-src.

  5. removed
    good first issueSmall tasks with clear documentation about how and in which place you need to fix things in.
    on Jul 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions