agdsn / sipa

The Supreme Information Providing Application
MIT License
13 stars 10 forks source link

Move inline CSS / JS to files #453

Closed FestplattenSchnitzel closed 11 months ago

FestplattenSchnitzel commented 1 year ago

so 'unsafe-inline' can be removed from the CSPs for better security enforcement.

FestplattenSchnitzel commented 11 months ago

Unfortunately, this does not seem to be possible with pygal which we use for the traffic chart in the usersuite, see sipa/utils/graph_utils.py.