Skip to content

CSP headers: remove unsafe-inline #137

@alextreme

Description

@alextreme

Thema / Theme

API

Omschrijving / Description

In the CSP headers we currently have unsafe-inlines:

CSP_STYLE_SRC = CSP_DEFAULT_SRC + [

This was introduced last year with some urgency after the initially adding of admin CSP headers due to breaking various admin/redoc functionality in our components:

open-zaak/open-notificaties#190
#68

Original request from AMS:

#42

Client would like to revisit this and remove the unsafe-inlines for OZ, OK, ON, Obj, OT. And also OAB, but this component doesn't use OAF afaik

Aanvullende opmerkingen / Additional context

This time we should tackle this on a component-by-component basis, and only after approval and release of one component apply this more broader. This to avoid the overhead we had last time when this was done across the board and had to be redone

Metadata

Metadata

Assignees

No one assigned

    Projects

    Status

    Waiting for approval

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions