You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Get rid of inline CSS and remove unsafe-inline gradually from controllers #1127
In this thread someone suggested creating a strict CSP. There is my humble suggestion to keep the CSP short. If we replace default-src with 'none', then it becomes too long.
Apache2:
Header set Content-Security-Policy "default-src 'self'; img-src data: 'self'; upgrade-insecure-requests;"
I am not using nginx so someone else can write its equivalent. I hope the suggestion is useful to authors who want to get rid of 'unsafe-inline' from script-src.