Skip to content

Conversation

@susnux
Copy link
Contributor

@susnux susnux commented Nov 17, 2023

Summary

Using strict-dynamic will invalidate every self allowed source, so it only makes sense together with nonce.
Otherwise browsers not supporting CSP 3.0 will break.

Checklist

@SystemKeeper
Copy link
Contributor

SystemKeeper commented Nov 17, 2023

Tested with Talk on iOS and Talk on Android and both work with this PR again!

@juliusknorr juliusknorr merged commit 330d9e3 into master Nov 19, 2023
@juliusknorr juliusknorr deleted the fix/csp-on-old-ua branch November 19, 2023 14:59
@blizzz blizzz mentioned this pull request Nov 20, 2023
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants