Kinto / Kinto/kinto

CSP prevent attachment preview for images in Admin UI

Open
#2,341 1 comment 0 reactions 0 assignees View on GitHub
bug stale want
Dominant language
Python
Stars
4.4k
Forks
437
Avg merge
1d 2h
Merged PRs (30d)
15

Description

`Content Security Policy: The page’s settings blocked the loading of a resource at https://firefox-settings-attachments-cdn.stage.mozaws.net/ma…e/product-integrity/1be52f5f-ce54-4471-85b4-44a7800fdfcd.png (“img-src”).`

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the image attachment preview failure in the Admin UI and inspect the Content Security Policy handling for the reported attachment URL. Done means the image preview loads without the reported img-src violation.

Written by the indexing model from the issue text.

Assessment

Domain
frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.