mirror of
				https://github.com/kevinveenbirkenbach/computer-playbook.git
				synced 2025-10-31 10:19:09 +00:00 
			
		
		
		
	Solved CSP bugs for echoserver
This commit is contained in:
		| @@ -20,6 +20,8 @@ csp: | ||||
|       unsafe-eval:    true | ||||
|     style-src: | ||||
|       unsafe-inline:  true | ||||
|     script-src: | ||||
|       unsafe-eval:    true | ||||
|   whitelist: | ||||
|     connect-src: | ||||
|       - wss://espocrm.{{ primary_domain }} | ||||
|   | ||||
| @@ -13,11 +13,14 @@ csp: | ||||
|     style-src: | ||||
|       - https://fonts.googleapis.com | ||||
|   flags: | ||||
|     script-src: | ||||
|       unsafe-eval:   true | ||||
|     script-src-elem: | ||||
|       unsafe-inline: true | ||||
|       unsafe-eval:   true | ||||
|     style-src: | ||||
|       unsafe-inline: true | ||||
|       unsafe-eval:   true | ||||
| domains: | ||||
|   aliases: | ||||
|     - "analytics.{{ primary_domain }}" | ||||
| @@ -7,6 +7,8 @@ features: | ||||
|   oidc:               true | ||||
| csp: | ||||
|   flags: | ||||
|     script-src-elem: | ||||
|       unsafe-inline:  true | ||||
|     script-src: | ||||
|       unsafe-inline:  true | ||||
|     style-src: | ||||
|   | ||||
| @@ -4,6 +4,8 @@ features: | ||||
|   portfolio_iframe:   false | ||||
| csp: | ||||
|   flags: | ||||
|     script-src: | ||||
|       unsafe-eval:    true | ||||
|     script-src-elem: | ||||
|       unsafe-inline:  true | ||||
|       unsafe-eval:    true | ||||
|   | ||||
| @@ -77,7 +77,7 @@ | ||||
|             (application_id): { | ||||
|               'csp': { | ||||
|                 'hashes': { | ||||
|                   'script-src': ( | ||||
|                   'script-src-elem': ( | ||||
|                     applications[application_id]['csp']['hashes'].get('script-src', []) | ||||
|                     + [ matomo_tracking_code_one_liner ] | ||||
|                   ) | ||||
|   | ||||
		Reference in New Issue
	
	Block a user