deltachat / deltachat-desktop

Email-based instant messaging for Desktop.
GNU General Public License v3.0
940 stars 166 forks source link

remove CSP styles 'unsafe-inline' exeption #2105

Closed Simon-Laux closed 1 year ago

Simon-Laux commented 3 years ago
Simon-Laux commented 3 years ago

Change: file scheme instead of dc scheme for loading themes since #2171

Simon-Laux commented 1 year ago

I don't really see this css CSP thing as a real security vulnerabilty. But If you can change my mind (show me how it can be abused in deltachat), I'll reconsider.