Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recommended CSP #103

Closed
gene-git opened this issue Jul 27, 2021 · 2 comments
Closed

Recommended CSP #103

gene-git opened this issue Jul 27, 2021 · 2 comments

Comments

@gene-git
Copy link

First - thank you for actively working on this project, It really is very much appreciated.

Wondering what your thoughts are around the most secure content security policy that can be used for Snappymail.
And do you have any plans / ideas to allow removal of stuff like 'unsafe-inline' (which seems to be needed for both style-src and script-src)?

thanks again

@the-djmaze
Copy link
Owner

the-djmaze commented Jul 28, 2021

unsafe-inline on the style-src is needed for email because html emails are self contained.
unsafe-inline & unsafe-eval on script-src might be dropped in the future when everything works with it (which it doesn't at the moment.

Tighten it even more is hardly impossible due to the nature of email (remote images for example).
But for the images there is the proxy feature, see #16

@gene-git
Copy link
Author

Thank you - and the earlier discussion was informative - you're definitely helping me slowly get up to speed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants