Skip to content

Conversation

@amazing4u
Copy link
Contributor

@amazing4u amazing4u commented Jul 6, 2024

Hi @Cordobo

Thank you for this great library!

Until now the user needs to enable connect-src for data: and weaken the security!

With this change i convert the base64-data-image-url in a blob-url without using fetch so you don't need to change the csp for connect-src!

More information:
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/connect-src
https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html

This fixes #196

…eed for connect-src data: in content security policy
@Cordobo Cordobo self-requested a review July 25, 2024 19:46
@Cordobo Cordobo added this to the 18.x milestone Jul 25, 2024
@Cordobo Cordobo merged commit 3b8b5aa into Cordobo:main Jul 25, 2024
@Cordobo Cordobo self-assigned this Jul 25, 2024
Cordobo added a commit that referenced this pull request Jul 25, 2024
Cordobo added a commit that referenced this pull request Jul 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

content security policies violation issue

2 participants