Nautobot - Content Security Policy best practice deviation - Unsafe Inline #5607
TheBirdsNest
started this conversation in
General
Replies: 1 comment
-
@TheBirdsNest thanks for bringing this up. We are aware of the need to introduce a default |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello Community!
I am deploying Nautobot in my organisation and we have a security policy that the 'Content-Security-Policy' directive must be present in the header without 'unsafe-inline' options configured for any element.
When applying this, the styling in Nautobot is broken and I see a large amount of errors.
I can see that styles have been configured inline.
It well understood that 'unsafe-inline' should be avoided to mitigate injection attacks.
https://content-security-policy.com/unsafe-inline/
Does anyone know if something is being done about this already?
Thanks,
Lawrence
Beta Was this translation helpful? Give feedback.
All reactions