You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/client/web
Will Norris e537d304ef client/web: relax CSP restrictions for manage client
Don't return CSP headers in dev mode, since that includes a bunch of
extra things like the vite server.

Allow images from any source, which is needed to load user profile
images.

Allow 'unsafe-inline' for various inline scripts and style react uses.
We can eliminate this by using CSP nonce or hash values, but we'll need
to look into the best way to handle that. There appear to be several
react plugins for this, but I haven't evaluated any of them.

Updates tailscale/corp#14335

Signed-off-by: Will Norris <will@tailscale.com>
11 months ago
..
build client/web: clean up assets handling 1 year ago
src client/web: move auth session creation out of /api/auth 11 months ago
assets.go client/web: switch to using prebuilt web client assets 1 year ago
auth.go client/web: move more session logic to auth.go 11 months ago
index.html client/web: always use new web client; remove old client 1 year ago
package.json build(deps-dev): bump postcss from 8.4.27 to 8.4.31 in /client/web 11 months ago
postcss.config.js client/web: add tailwind styling to react app 1 year ago
qnap.go client/web: limit authorization checks to API calls 11 months ago
synology.go client/web: limit authorization checks to API calls 11 months ago
tailwind.config.js client/web: add tailwind styling to react app 1 year ago
tsconfig.json client/web: add debug mode for web client ui updates 1 year ago
vite.config.ts client/web: switch to using prebuilt web client assets 1 year ago
web.go client/web: relax CSP restrictions for manage client 11 months ago
web_test.go client/web: add some security checks for full client 11 months ago
yarn.lock build(deps-dev): bump postcss from 8.4.27 to 8.4.31 in /client/web 11 months ago