summaryrefslogtreecommitdiffstats
path: root/tracker
diff options
context:
space:
mode:
authorguilhem <guilhem@web>2016-04-07 19:28:18 +0200
committerFripost Admins <admin@fripost.org>2016-04-07 19:28:18 +0200
commite53be466f921b89ef475543434fafa5e9d89c3de (patch)
tree3fa989e3bfc35b9d30672a2f196b8f0a3b0fc5d7 /tracker
parent8ca6c89b6f0148ce0f320e7c784e2c1bee929ad1 (diff)
really close
Diffstat (limited to 'tracker')
-rw-r--r--tracker/CSP_too_strict.mdwn5
1 files changed, 3 insertions, 2 deletions
diff --git a/tracker/CSP_too_strict.mdwn b/tracker/CSP_too_strict.mdwn
index 2b27eff..308754d 100644
--- a/tracker/CSP_too_strict.mdwn
+++ b/tracker/CSP_too_strict.mdwn
@@ -10,5 +10,6 @@ Oh wait, that's weird: it seems to block data-urls too:
Content Security Policy: The page's settings blocked the loading of a resource at data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw== ("img-src https://mail.fripost.org").
```
-I'm not excited about allowing browsers to load images from arbitrary sources, but hopefully roundcube's anti-XSS filter is good enough. I've also checked with the [Email Privacy Tester](https://emailprivacytester.com/)
-that other external ressources blocked by the CSP are probably malicious. Let's call that [done](https://git.fripost.org/fripost-ansible/commit/?id=c90ae1fe9d40a0271844d321a7a54ee219735ccf). -- [[guilhem]]
+I'm not too excited about allowing browsers to load images from arbitrary sources, but [did it anyway](https://git.fripost.org/fripost-ansible/commit/?id=c90ae1fe9d40a0271844d321a7a54ee219735ccf) with the hope that roundcube's anti-XSS filter is good enough.
+I've also checked with the [Email Privacy Tester](https://emailprivacytester.com/) that other external resources blocked by the CSP are probably malicious.
+[[closed]]. -- [[guilhem]]