Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
erp5 erp5
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Labels
    • Labels
  • Merge requests 141
    • Merge requests 141
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Environments
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedi
  • erp5erp5
  • Merge requests
  • !1821

Merged
Created Sep 08, 2023 by Jérome Perrin@jeromeOwner

Update officejs support request app for strict CSP

  • Overview 1
  • Commits 7
  • Pipelines 2
  • Changes 61

This is a first step to stop using "unsafe" web sections.

This updates support request app to not require script-src: unsafe-eval and style-src: unsafe-inline in the CSP. Dropping script-src: unsafe-eval is made possible by using domsugar instead of handlebars for dynamic content. Dropping style-src: unsafe-inline by using CSS files instead of inline style attributes in the DOM. One minor regression is that the tooltips from the graph on the front page gadget will cause warning because of unsafe-inline and not render the series color.

This application was also modernized a bit, it now uses the HTML viewer gadget to display post contents and supports translation.

Edited Sep 08, 2023 by Jérome Perrin
Assignee
Assign to
Reviewer
Request review from
None
Milestone
None
Assign milestone
Time tracking
Source branch: feat/support-request-csp-l10n
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7