Hide 'unsafe-eval' from style-src config

Created on 13 June 2024, 10 months ago
Updated 28 June 2024, 9 months ago

Problem/Motivation

The CSP spec only defines 'unsafe-eval' as valid in parsing whether a script should be executed.

Proposed resolution

Remove 'unsafe-eval' from the options available for style-src on the config form.

Remaining tasks

User interface changes

API changes

Data model changes

📌 Task
Status

Fixed

Version

2.0

Component

Code

Created by

🇨🇦Canada gapple

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024