about summary refs log tree commit diff
path: root/config/initializers/content_security_policy.rb
AgeCommit message (Expand)Author
2023-03-31Autofix Rubocop Style/IdenticalConditionalBranches (#24322)Nick Schonning
2022-11-17Add form-action CSP directive (#20781)Claire
2022-11-15Fix wrong directive `unsafe-wasm-eval` to `wasm-unsafe-eval` (#20729)Eugen Rochko
2022-11-15Use "unsafe-wasm-eval" instead of "unsafe-eval" in script-src CSP (#20606)prplecake
2022-10-26Add "unsafe-eval" to script-src CSP (#18817)prplecake
2022-03-14Fix LetterOpennerWeb CSP (#17770)Yamagishi Kazutoshi
2021-04-09Fix autoloading deprecation warnings from Rails 6 (#16010)Eugen Rochko
2021-03-24Update Mastodon to Rails 6.1 (#15910)Claire
2020-07-07Fix hashtag column options styling (#14247)ThibG
2020-05-08Remove 'unsafe-inline' from Content-Security-Policy style-src (#13679)ThibG
2020-05-04Fix PgHero Content-Security-Policy when CDN_HOST is used (#13595)ThibG
2020-03-27Fix OCR not working on Safari because of unsupported worker-src CSP (#13323)ThibG
2019-08-19Fix CSP needlessly allowing blob URLs in script-src (#11620)ThibG
2019-08-16Fix media host not being included in connect-src for OCR (#11577)Eugen Rochko
2019-08-15Add OCR tool to media editing modal (#11566)Eugen Rochko
2018-10-12Add manifest_src to CSP, add blob to connect_src (#8967)ThibG
2018-10-12Fix CSP headers blocking media and development environment (#8962)Eugen Rochko
2018-10-11Set Content-Security-Policy rules through RoR's config (#8957)ThibG
2018-04-12Upgrade Rails to version 5.2.0 (#5898)Yamagishi Kazutoshi