browse: fix Content-Security-Policy warnings in Firefox #6443
+1
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR addresses the Content-Security-Policy warnings in Firefox: #6425 (comment)
The following changes have been made:
Remove
strict-dynamic
fromstyle-src
:Remove
block-all-mixed-content
:See also: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/block-all-mixed-content
strict-dynamic
,https:
, andhttp:
fromscript-src
:After these changes, only the following warning will remain due to the presence of'unsafe-inline'
withinscript-src
for backward compatibility with browsers not supporting Content-Security-Policy Version 3 (such as Internet Explorer 11):> Content-Security-Policy: Ignoring “'unsafe-inline'” within script-src: nonce-source or hash-source specifiedUnfortunately, Firefox will log this directive being ignored. We must make a trade-off between this warning and maintaining backward compatibility.See also: https://developer.chrome.com/docs/lighthouse/best-practices/csp-xss/#ensure_csp_is_backwards_compatible
UPDATE:
4. Remove
unsafe-inline
fromscript-src
:No more Content-Security-Policy warnings in Firefox.
The adjusted
browse.html
is currently active on my playground:https://alma.stbu.net/testing-something/