Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Merge requests 142
    • Merge requests 142
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedinexedi
  • erp5erp5
  • Merge requests
  • !1821

Update officejs support request app for strict CSP

  • Review changes

  • Download
  • Patches
  • Plain diff
Merged Jérome Perrin requested to merge feat/support-request-csp-l10n into master Sep 08, 2023
  • Overview 1
  • Commits 7
  • Pipelines 2
  • Changes 61

This is a first step to stop using "unsafe" web sections.

This updates support request app to not require script-src: unsafe-eval and style-src: unsafe-inline in the CSP. Dropping script-src: unsafe-eval is made possible by using domsugar instead of handlebars for dynamic content. Dropping style-src: unsafe-inline by using CSS files instead of inline style attributes in the DOM. One minor regression is that the tooltips from the graph on the front page gadget will cause warning because of unsafe-inline and not render the series color.

This application was also modernized a bit, it now uses the HTML viewer gadget to display post contents and supports translation.

Edited Sep 08, 2023 by Jérome Perrin
Assignee
Assign to
Reviewers
Request review from
Time tracking
Source branch: feat/support-request-csp-l10n
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7