Closed
Conversation
Always set unsafe-inline for javascript as well. Newer browsers that support the nonce will ignore this see https://csp.withgoogle.com/docs/strict-csp.html https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/script-src This means that older browsers will just execute the script but modern browsers will check for the nonce and ignoring the unsafe-inline. Basically this is the backwards compatibility mode. Signed-off-by: Roeland Jago Douma <[email protected]>
Member
|
Please open the backport PR. |
Member
|
Signed-off-by: Roeland Jago Douma <[email protected]>
Member
|
We should make sure that it works on all those fancy built in browsers on Android and on the desktop to not break the login flow :/ Maybe add a little banner on top to see if the JS is not loaded - otherwise it feels strange because the buttons just don't work. A little message that is hidden by JS somehow? |
Member
Author
|
ok lets not do this right away for 14. I need time to think to come up with a proper solution. |
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Always set unsafe-inline for javascript as well. Newer browsers that
support the nonce will ignore this see
https://csp.withgoogle.com/docs/strict-csp.html
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/script-src
This means that older browsers will just execute the script but modern
browsers will check for the nonce and ignoring the unsafe-inline.
Basically this is the backwards compatibility mode.
Signed-off-by: Roeland Jago Douma [email protected]