Skip to content

Remove unsafe-inline from CSP #344

@theseion

Description

@theseion

We currently use a couple of inline scripts (e.g. for fontawesome) that requires unsafe-inline in the Content Security Policy header.

Acceptance criteria

  • remove unsafe-inline from the CSP
  • use hashes / nonces to allow loading of those resources that would be blocked by unsafe-inline

See also #343

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions