You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The style-src hash is necessary for the metadata page; the script-src: unsafe-inline for the json in the WAYF. Both should be fixed (by using an external stylesheet and by loading the json from an API-endpoint, respectively):
This CSP header is reported to work:
The
style-src
hash is necessary for the metadata page; thescript-src: unsafe-inline
for the json in the WAYF. Both should be fixed (by using an external stylesheet and by loading the json from an API-endpoint, respectively):unsafe-inline
CSP because of embedded json/js OpenConext-engineblock#1331frame-ancestors
needs careful consideration.The text was updated successfully, but these errors were encountered: