mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-06-15 19:59:11 +08:00
* FEATURE: allow plugins and themes to extend the default CSP For plugins: ``` extend_content_security_policy( script_src: ['https://domain.com/script.js', 'https://your-cdn.com/'], style_src: ['https://domain.com/style.css'] ) ``` For themes and components: ``` extend_content_security_policy: type: list default: "script_src:https://domain.com/|style_src:https://domain.com" ``` * clear CSP base url before each test we have a test that stubs `Rails.env.development?` to true * Only allow extending directives that core includes, for now |
||
|---|---|---|
| .. | ||
| csp_extension | ||
| custom_locales | ||
| my_plugin | ||