oxidecomputer / oxidecomputer/console

Tracking: remove `style-src: 'unsafe-inline'` from CSP

Open
#2,183 0 comments 0 reactions 1 assignee View on GitHub

@iliana is already working on this.

Since Apr 23, 2024.

Dominant language
TypeScript
Stars
228
Forks
22
Avg merge
19h 42m
Merged PRs (30d)
32

Description

  • xterm.js: Requires unsafe-inline for the default renderer. Could switch to another renderer, write our own renderer, or contribute nonce support upstream (this was their original plan, but they tried constructed style sheets instead, which broke VS Code...)

See https://github.com/xtermjs/xterm.js/issues/4445

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.