Add CSP config #8
Loading…
Reference in New Issue
No description provided.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This is the CSP header from karrot.world:
It needs to be configured based on configuration variables though, we currently generate it from an ansible task (see
26e36067c4/roles/karrot-backend/tasks/main.yml (L32-L67)
).The firebase/fcm is going away soon (next karrot release has replaced that with web push implementation).
The report URI should be a configuration option, and only be included if present.
I think the script
unsafe-eval
can go away now too (given https://github.com/karrot-dev/karrot-frontend/issues/2522).I'm not sure why the
unsafe-inline
for style-src is there, potentially not needed now.