Skip to content

Conversation

@runephilosof-abtion
Copy link

Improves on #225 (PR set as draft, to wait for the other PR to be merged)

Restrict the hosts that the widget is allowed to contact.

Also, set stylesheet from cloudflare to be loaded over https, also in
development.

Unset it or set it to `http: https:` to keep the previous behavior.

For self-hosting you would probably want to set it to
`https://your.domain`.

Do not allow iframing the frontend
Restrict the hosts that the widget is allowed to contact.

Also, set stylesheet from cloudflare to be loaded over https, also in
development.
@runephilosof-abtion
Copy link
Author

The script-src 'unsafe-inline' can be removed once #228 is merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant