From 6d5f44d489e652743d4596aba0b2c3bd3f3ee250 Mon Sep 17 00:00:00 2001 From: Pierre de La Morinerie Date: Tue, 22 Feb 2022 17:17:55 +0100 Subject: [PATCH] config: translate the CSP comments from french to english --- .../initializers/content_security_policy.rb | 23 +++++++++---------- 1 file changed, 11 insertions(+), 12 deletions(-) diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb index c798a1bed..f0021b58b 100644 --- a/config/initializers/content_security_policy.rb +++ b/config/initializers/content_security_policy.rb @@ -5,22 +5,20 @@ # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy Rails.application.config.content_security_policy do |policy| - # Whitelist image images_whitelist = ["*.openstreetmap.org", "*.cloud.ovh.net", "*"] images_whitelist << URI(DS_PROXY_URL).host if DS_PROXY_URL.present? images_whitelist << URI(MATOMO_IFRAME_URL).host if MATOMO_IFRAME_URL.present? policy.img_src(:self, :data, :blob, *images_whitelist) - # Whitelist JS: nous, sendinblue et matomo - # miniprofiler et nous avons quelques boutons inline :( + # Javascript: allow us, SendInBlue and Matomo. + # We need unsafe_inline because miniprofiler and us have some inline buttons :( scripts_whitelist = ["*.sendinblue.com", "*.crisp.chat", "crisp.chat", "*.sibautomation.com", "sibautomation.com", "cdn.jsdelivr.net", "maxcdn.bootstrapcdn.com", "code.jquery.com"] scripts_whitelist << URI(MATOMO_IFRAME_URL).host if MATOMO_IFRAME_URL.present? policy.script_src(:self, :unsafe_eval, :unsafe_inline, :blob, *scripts_whitelist) - # Pour les CSS, on a beaucoup de style inline et quelques balises