about summary refs log tree commit diff
path: root/src/admin/mod.rs
diff options
context:
space:
mode:
authorVika <vika@fireburn.ru>2025-01-02 07:07:14 +0300
committerVika <vika@fireburn.ru>2025-01-02 07:07:14 +0300
commitf358d8f819c4177a9d716d7e33603e644a9a0c99 (patch)
tree96e6cd24af29d007c531bc1d7c29135bfcd13533 /src/admin/mod.rs
parent78f8de236b7ab9755f0212a740d341a2518968da (diff)
downloadkittybox-f358d8f819c4177a9d716d7e33603e644a9a0c99.tar.zst
Set a minimal CSP
 - Styles and scripts can now only be loaded from Kittybox
   (hint: use the media endpoint if you wish to upload custom CSS)
 - Inline scripts are now completely prohibited
   (this means it's safe to show arbitrary HTML from Webmentions)
 - `<base>` element is prohibited (who uses that anyway?)
 - Loading anything else is only allowed via HTTPS

Change-Id: I285a18b71dd9860416b18dd0e88f8fe7c8511e0b
Diffstat (limited to 'src/admin/mod.rs')
0 files changed, 0 insertions, 0 deletions