Skip to content

Conversation

kushthedude
Copy link
Member

Fixes #3839

@auto-label auto-label bot added the fix label Jan 23, 2020
@iamareebjamal
Copy link
Member

CSP needs to change a lot. There are other violations as well. Besides, CSP statically lists heroku and local apps as allowed. This should not be the case, it should extract origin from API_BASE_URL and use that to dynamically generate CSP like in case of SENTRY_DSN

@kushthedude
Copy link
Member Author

CSP needs to change a lot. There are other violations as well. Besides, CSP statically lists heroku and local apps as allowed. This should not be the case, it should extract origin from API_BASE_URL and use that to dynamically generate CSP like in case of SENTRY_DSN

@iamareebjamal What about this https://github.com/rwjblue/ember-cli-content-security-policy

@iamareebjamal
Copy link
Member

Aren't we already using a dependency? How does this help?

@iamareebjamal iamareebjamal changed the title fix: Adding omise cdn in CSP fix: Add omise cdn in CSP Jan 30, 2020
@iamareebjamal iamareebjamal merged commit 7476457 into fossasia:development Jan 30, 2020
@kushthedude kushthedude deleted the omi branch January 30, 2020 21:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Omise Checkout is not accessible due to CSP

2 participants