mirror of https://github.com/tailscale/tailscale/
client/web: relax CSP restrictions for manage client
Don't return CSP headers in dev mode, since that includes a bunch of extra things like the vite server. Allow images from any source, which is needed to load user profile images. Allow 'unsafe-inline' for various inline scripts and style react uses. We can eliminate this by using CSP nonce or hash values, but we'll need to look into the best way to handle that. There appear to be several react plugins for this, but I haven't evaluated any of them. Updates tailscale/corp#14335 Signed-off-by: Will Norris <will@tailscale.com>pull/10129/head
parent
5de8650466
commit
e537d304ef
Loading…
Reference in New Issue