Implement the script-src-attr policy

Created on 23 March 2022, over 3 years ago
Updated 6 June 2025, 2 months ago

Problem/Motivation

The current seckit CSP module does not support the policy script-src-attr, described in the W3C definition: https://w3c.github.io/webappsec-csp/#script-src-attr

Steps to reproduce

None;

Proposed resolution

Implement the script-src-attr field and header

Remaining tasks

- Add the field to the settings page
- Add the header with the user defined values

User interface changes

Add the field to the settings page

✨ Feature request
Status

Needs review

Version

2.0

Component

Code

Created by

πŸ‡§πŸ‡·Brazil barone Belo Horizonte

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024