Commit Graph

40 Commits (07fe9c8817e176691e65168f55ad2d07c9036a8c)

Author SHA1 Message Date
Niklas Fiekas e343d23e7e avoid script-src unsafe-inline almost everywhere 2021-11-13 23:57:37 +01:00
Niklas Fiekas 7c4926fcf9 make csp compatible with ancient browsers 2021-11-01 12:43:56 +01:00
Thibault Duplessis d533767784 analysis wikibooks theory POC 2021-10-06 12:06:06 +02:00
Niklas Fiekas aba7710e57 mirror also specialized google fonts (fixes #8701) 2021-05-07 11:00:41 +02:00
Thibault Duplessis 9c34d433f9 replace recaptcha with hcaptcha - closes #3530 2021-04-08 16:33:41 +02:00
Niklas Fiekas 0dc4e037f5 put reminder that twitch must come last in csp 2021-01-25 14:18:15 +01:00
Thibault Duplessis 8ceca8f90d don't overwrite image CSP with twitch CSP 2020-11-02 17:45:33 +01:00
Thibault Duplessis 0027356cb0 allow any WS in /dgt/play CSP 2020-09-08 15:25:35 +02:00
Thibault Duplessis d5ef516f7b DGT CSP 2020-09-08 14:04:11 +02:00
Thibault Duplessis 20dd8d2349 autoformat code 2020-07-22 12:52:52 +02:00
Niklas Fiekas fb49bf223c ditch csp reporting 2020-07-09 17:21:50 +02:00
Thibault Duplessis 5488a09548 scalafmt 2.5 2020-05-05 22:11:15 -06:00
Niklas Fiekas 47950d54c6 factor out csp for webassembly 2019-12-20 13:14:07 +01:00
Thibault Duplessis ff1cc70bef reformat with scalafmt 2019-12-13 08:37:32 -06:00
Niklas Fiekas c329a482b7 downsample csp reports 2019-12-04 12:08:35 +01:00
Niklas Fiekas ba661730e7 enable csp reporting 2019-12-02 17:59:42 +01:00
Thibault Duplessis 4b64220f8a directly link to the spreadshirt shop instead of embedding - fixes #5441
it lets spreadshirt handle the geo redirect
2019-08-25 00:48:00 +02:00
Thibault Duplessis 9090afd491 Merge branch 'master' of github.com:ornicar/lila into palantir
* 'master' of github.com:ornicar/lila:
  Use nonEmpty
  Only show more button if timeline exists
  Use a class instead of an attribute
  Remove accidental css
  tweak chess variant row in /features
  Remove filter numbers and colour the filter button icon instead
  no need for unsafe-inline fallback for nonce since safari 10
  nav implies role navigation
  spec recommends sligtly longer nonces
  fix html syntax
  Removed ALL tabs this time
  Updated renderSan()
  Add space between anon and number so it is now Anonymous (1)
  Replace tabs with spaces (oops)
  Leaderboard hover transition to blue
  Tournament schedule links blue on hover
2019-08-08 10:38:44 +02:00
Thibault Duplessis 99bd6bb539 palantir WIP 2019-08-07 17:10:30 +02:00
Niklas Fiekas 831c2df2ec no need for unsafe-inline fallback for nonce since safari 10 2019-08-05 23:17:14 +02:00
Niklas Fiekas 697f8491af csp: allow framing twitter gifs (closes #5185) 2019-06-12 16:25:21 +02:00
Thibault Duplessis a7bd00c8fa fix signup recaptcha 2018-12-06 09:55:11 +07:00
Thibault Duplessis 0e228891e8 more template rewrite 2018-12-03 08:07:16 +07:00
Thibault Duplessis b5240abd78 fix #4728 2018-11-30 16:19:59 +07:00
Thibault Duplessis 35d76972df prismic preview seems to use http:// 2018-11-29 13:52:22 +07:00
Thibault Duplessis e328d07e31 fix prismic tweeter embeds 2018-11-29 12:00:04 +07:00
Thibault Duplessis fbf88293e6 update CSP for prismic editors 2018-11-27 08:51:11 +07:00
Thibault Duplessis 71774d9817 fix blog CSP again 2018-11-17 19:36:17 +07:00
Thibault Duplessis afae01da54 update CSP directives for prismic editors 2018-11-17 19:36:17 +07:00
Niklas Fiekas fe959e68a4 csp: we never use <base> 2018-07-28 05:16:51 +02:00
Niklas Fiekas 4be94e2589 work around broken csp in safari 2018-06-28 14:53:45 +02:00
Niklas Fiekas 9851210b90 csp: child-src is deprecated 2018-06-20 22:34:23 +02:00
Thibault Duplessis c06b05cc24 fix /get-fishnet CSP 2018-05-11 01:37:33 +02:00
Niklas Fiekas 2e214dc6ea csp: allow twitter embeds in blog posts 2018-05-09 12:06:09 +02:00
Niklas Fiekas c67bef7486 misc improvements from review 2018-05-08 01:49:10 +02:00
Niklas Fiekas deb6c5ee5d fix csp for video embeds 2018-05-07 19:53:50 +02:00
Niklas Fiekas 68e1ea8c40 liberal csp for spreadshirt 2018-05-07 19:42:35 +02:00
Niklas Fiekas 39e65f16eb fix csp on strip checkout page 2018-05-07 19:35:16 +02:00
Niklas Fiekas a9403f93f8 apply csp almost everywhere 2018-05-07 19:21:33 +02:00
Niklas Fiekas 55d1475945 add a content security policy 2018-05-07 18:32:18 +02:00