This repository was archived by the owner on Nov 16, 2023. It is now read-only.
Implemented a simple content security policy using <meta> tag.#145
Open
redox-alpha wants to merge 1 commit intomicrosoft:masterfrom
Open
Implemented a simple content security policy using <meta> tag.#145redox-alpha wants to merge 1 commit intomicrosoft:masterfrom
redox-alpha wants to merge 1 commit intomicrosoft:masterfrom
Conversation
Implemented a content security policy using <meta> tag, which only permits queries to the GitHub api. In addition, two of the inlined javascipt snippets have been moved to external files. Images can only be loaded from Microsoft's CDN.
Author
|
That nonce should be a hash, but in this particular project it's probably better not to |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implemented a content security policy using tag, which
only permits queries to the GitHub api. In addition, two of
the inlined javascipt snippets have been moved to external
files. Images can only be loaded from Microsoft's CDN.