Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP header adjustments (backport #3068) #3076

Merged
merged 4 commits into from
Jul 21, 2021

Conversation

mergify[bot]
Copy link

@mergify mergify bot commented Jul 21, 2021

This is an automatic backport of pull request #3068 done by Mergify.

AP-1507


Mergify commands and options

More conditions and actions can be found in the documentation.

You can also trigger Mergify actions by commenting on this pull request:

  • @Mergifyio refresh will re-evaluate the rules
  • @Mergifyio rebase will rebase this PR on its base branch
  • @Mergifyio update will merge the base branch into this PR
  • @Mergifyio backport <destination> will backport this PR on <destination> branch

Additionally, on Mergify dashboard you can:

  • look at your merge queues
  • generate the Mergify configuration with the config editor.

Finally, you can contact us on https://mergify.io/

Remove frame-acestors completely because it isn't included into an
iframe anymore. If this is still required the CSP settings can be
adjusted via a command line parameter.

More important don't allow executing javascript from inline html. Only
from references javascript files.

But allow to load CSS from inline <style> elements via style-src-elem
(not supported by firefox yet) and style-src CSP settings.

Fixes AP-1507

(cherry picked from commit 9c6bd5b)
(cherry picked from commit 279466b)
Froma https://create-react-app.dev/docs/advanced-configuration

> By default, Create React App will embed the runtime script into
> index.html during the production build. When set to false, the script
> will not be embedded and will be imported as usual. This is normally
> required when dealing with CSP.

(cherry picked from commit 44c7121)
(cherry picked from commit a6a9cea)
@mergify mergify bot requested a review from a team as a code owner July 21, 2021 06:38
@bjoernricks bjoernricks merged commit 1133888 into gsa-21.04 Jul 21, 2021
@bjoernricks bjoernricks deleted the mergify/bp/gsa-21.04/pr-3068 branch July 21, 2021 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant