Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Content Security Policy #55

Open
oupala opened this issue Jul 26, 2021 · 0 comments
Open

Content Security Policy #55

oupala opened this issue Jul 26, 2021 · 0 comments

Comments

@oupala
Copy link

oupala commented Jul 26, 2021

When enabling Content Security Policy on the webserver that serves epubjs-reader, unsafe-inline has to be enabled as epubjs-reader is including some js and some css in the html.

Do you think it could be possible to remove this requirement, hence making epubjs-reader mose secure and reliable?

unsafe-inline and unsafe-eval are obviously a bad habits and they could be easily avoided by moving css and js code un css and js files.

More informations on demande if you need some.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant