GetPublii / Publii

The most intuitive Static Site CMS designed for SEO-optimized and privacy-focused websites.
https://getpublii.com
GNU General Public License v3.0
6.06k stars 407 forks source link

[Feature Request]: Finetune for Content Security Policy #1489

Open brzGatsu opened 2 months ago

brzGatsu commented 2 months ago

Feature Description

With publii it is currently not possible to tune the CSP response header up to maximum safety. Mozilla Observatory recommends to not use any inline styles or inline scripts. Both publii and the technews theme make use of these (i.e. for lazy loading) which forces me to set "unsafe-inline" in the CSP.