Nautobot - Content Security Policy best practice deviation - Unsafe Inline #5607
TheBirdsNest
started this conversation in
General
Replies: 1 comment 1 reply
-
@TheBirdsNest thanks for bringing this up. We are aware of the need to introduce a default |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Community!
I am deploying Nautobot in my organisation and we have a security policy that the 'Content-Security-Policy' directive must be present in the header without 'unsafe-inline' options configured for any element.
When applying this, the styling in Nautobot is broken and I see a large amount of errors.
I can see that styles have been configured inline.
It well understood that 'unsafe-inline' should be avoided to mitigate injection attacks.
https://content-security-policy.com/unsafe-inline/
Does anyone know if something is being done about this already?
Thanks,
Lawrence
Beta Was this translation helpful? Give feedback.
All reactions