-
Notifications
You must be signed in to change notification settings - Fork 99
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CSP header adjustments (backport #3068) #3075
Conversation
@Mergifyio rebase |
Remove frame-acestors completely because it isn't included into an iframe anymore. If this is still required the CSP settings can be adjusted via a command line parameter. More important don't allow executing javascript from inline html. Only from references javascript files. But allow to load CSS from inline <style> elements via style-src-elem (not supported by firefox yet) and style-src CSP settings. Fixes AP-1507 (cherry picked from commit 9c6bd5b)
(cherry picked from commit 279466b)
Froma https://create-react-app.dev/docs/advanced-configuration > By default, Create React App will embed the runtime script into > index.html during the production build. When set to false, the script > will not be embedded and will be imported as usual. This is normally > required when dealing with CSP. (cherry picked from commit 44c7121)
(cherry picked from commit a6a9cea)
9c8b0c7
to
b08565f
Compare
Command
|
Codecov Report
@@ Coverage Diff @@
## master #3075 +/- ##
===========================================
+ Coverage 36.73% 56.42% +19.69%
===========================================
Files 991 1036 +45
Lines 22191 25168 +2977
Branches 6110 7197 +1087
===========================================
+ Hits 8151 14202 +6051
+ Misses 12715 9910 -2805
+ Partials 1325 1056 -269
Continue to review full report at Codecov.
|
This is an automatic backport of pull request #3068 done by Mergify.
AP-1507
Mergify commands and options
More conditions and actions can be found in the documentation.
You can also trigger Mergify actions by commenting on this pull request:
@Mergifyio refresh
will re-evaluate the rules@Mergifyio rebase
will rebase this PR on its base branch@Mergifyio update
will merge the base branch into this PR@Mergifyio backport <destination>
will backport this PR on<destination>
branchAdditionally, on Mergify dashboard you can:
Finally, you can contact us on https://mergify.io/