Improve CSP Documentation & Consider Full CSP Compliance in Plotly.js
オープン
@emilykl がすでに取り組んでいます。
2025年1月29日 から。
cs
documentation
feature
P1
- 主要言語
- JavaScript
- スター
- 18.3k
- フォーク
- 2k
- 平均マージ
- 2日 12時間
- マージ済み PR(30日)
- 28
説明
Title: Improve CSP Documentation & Consider Full CSP Compliance in Plotly.js
Description
Plotly.js provides a strict CSP bundle for users with strong Content Security Policies (CSP), but clear documentation is missing on:
- What’s included/excluded in the strict bundle
- Known limitations and workarounds
Enterprise customers and community users (e.g., this forum post) have requested better CSP support and clarity. The strict bundle exists (plotly-strict.js), but its usage is not well-documented.
Proposed Actions
- Document the strict bundle’s capabilities, limitations, and integration steps.
- Provide examples for CSP-compliant usage in Dash & JS.
- Evaluate full CSP compliance for Plotly.js instead of maintaining a separate bundle.
- Internal enterprise customers have requested a fully CSP-compliant version.
- Can the main plotly.js bundle be refactored to remove
evaland inline scripts?
Why This Matters
- CSP restrictions block adoption in security-sensitive environments.
- Clear documentation would prevent confusion and production roadblocks.
- Growing demand from enterprises & community users for strict CSP support.
Can the team consider making the main bundle fully CSP-compliant? Are there technical challenges or funding requirements for this? 🚀
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
評価
この issue はまだ評価されていません。