-
Notifications
You must be signed in to change notification settings - Fork 217
Closed
5 / 55 of 5 issues completedLabels
opsDocker, nginx, ops to deploy CentralDocker, nginx, ops to deploy Central
Description
Originally introduced in getodk/central-backend#313, there seem to be some false-positives.
Reported violations include:
- oidc: csp: style-src-elem directive violated on login #1235
- Add Content-Security-Policy for WebForms #1130
- Map violates Content Security Policy #1403
- CSP: allow google translate for all pages #1129
- App user QR code violates CSP directive #629 - Content-Security-Policy: allow images from data: URLs #772
-
Blocked 'connect' from 'maps.googleapis.com'- enketo: Content-Security-Policy: relax connect-src rule for Google Maps #879 -
Blocked 'image' from 'tile.openstreetmap.org'- enketo: Content-Security-Policy: allow OpenStreetMap tile images #880 -
Blocked style attribute from 'inline:'- enketo: relax Content-Security-Policy for inline style attributes #771
Some reported violations may be the result of google chrome's built-in translator, or google translate.
Reactions are currently unavailable
Sub-issues
Metadata
Metadata
Assignees
Labels
opsDocker, nginx, ops to deploy CentralDocker, nginx, ops to deploy Central
Type
Projects
Status
✅ done