Skip to content

Conversation

contolini
Copy link
Member

Removes 'unsafe_inline' from the style_src nginx directive to prevent inline stylesheets from being loaded.

See #4529 and #2480

Changes

  • Updates nginx to block inline styles.

Testing

  1. Tests should pass against dev and everything should behave as expected.

Copy link
Contributor

@billhimmelsbach billhimmelsbach left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Huh this is a weird one, since everything works fine now with it removed? Did ya figure out why in the ticket screenshots it was broken?

Removes 'unsafe_inline' from the style_src nginx directive to prevent
inline stylesheets from being loaded.

See https://ghe/HMDA-Operations/hmda-devops/issues/4529
Fixes #2480
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants