agusmakmun / agusmakmun/django-markdown-editor

The editor does not work when setting a Content Security Policy

オープン
#218 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
JavaScript
スター
901
フォーク
1.3k
PR マージ指標
30日以内にマージされた PR はありません

説明

## Details

- OS (Operating System) version: Ubuntu
- Browser and browser version: Chromium & Firefox
- Django version: 4.1.7
- Martor version & theme: martor = 1.6.19

### Steps to reproduce

1. Set a CSP header on your webserver, e.g.: `add_header Content-Security-Policy "default-src 'self';`
2. Open a django admin page with a field with the markdown editor

In the Browser console you see the error:
ace.js:5 Refused to apply inline style because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-NPmOMJ6Koi743g0BGW8ul25dqdhwdyelDGzO4sWLPbE='), or a nonce ('nonce-...') is required to enable inline execution. Note also that 'style-src' was not explicitly set, so 'default-src' is used as a fallback.
and
Refused to load the image 'data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

I expect the markdown editor work with security precautions in place.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。