-
Type: Bug
-
Status: In Review
-
Priority: Minor
-
Resolution: Unresolved
-
Affects Version/s: 3.0.x, 3.1.x
-
Tags:
-
Sprint:UI - 2024-8, UI COOLDOWN - 2024-7, UI COOLDOWN - 2024-9, UI - 2024-9, UI - 2024-12
-
Story Points:5
- object-src is missing from CSP.
- Evaluate if we can restrict object-src to 'none'
AC
-
-
- CSP policy must keep compatibility with existing applications
- To be tested with default UI
- To be tested with a customized UI configured in Nuxeo Studio Designer
- Specifically check for the import mechanism for which we are using a polyfill to keep compatibility
- CSP policy must keep compatibility with existing applications
-
1.
|
QA-task | Resolved | Pranit SadashivSotre |