-
Notifications
You must be signed in to change notification settings - Fork 446
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
移除对 CSP 响应头 'unsafe-inline' 的依赖 #220
Comments
Thanks for opening this issue, maintainers will get back to you as soon as possible! |
“不使用内联样式” 的说法不太准确,只要保证源文件不使用内联样式、内联样式表就行了。 JS 中利用元素的 JS 属性 |
这个issue不应关闭,还有一堆第三方js没有处理。 |
有道理 |
This thread has been automatically locked since there has not been any recent activity after it was closed. It is possible issue was solved or at least outdated. Feel free to open new for related bugs. |
Issue Checklist
Expected behavior
不使用内联样式和内联脚本。
Actual behavior
NexT 生成了一些内联样式和内联脚本,与 CSP 的最佳实践不合。
Steps to reproduce the behavior
(此 issue 不需要)
Other Information
以前的 NexT 仓库有相关 issue 讨论,问题一致,但现在问题在新仓库出现,故再开一个 issue。
The text was updated successfully, but these errors were encountered: