Open travjenkins opened 3 weeks ago
We should be really safe and start working on getting the UI to work with Trusted Types
Not 100% sure how we'll handle this yet - but we should try to make slow and steady progress.
Tooltip writes to the DOM
TMLScriptElement src|https://js.stripe.com/v3 HTMLScriptElement src|https://js.stripe.com/v3/fingerprinted/j
This one is weird cause we have it marked in the script-src HTMLScriptElement src|https://cdn.logr-ingest.com/logger-1.min
script-src
HTMLScriptElement src|https://www.googletagmanager.com/gtm.js?
Worker constructor|/static/editor.worker-e9368882.js Worker constructor|/static/json.worker-3dd12af9.js
Given the code around it I think this is Apache eCharts
We have the header in place but Chrome is still complaining about this. Not 100% sure what it is complaining about
... add_header Permissions-Policy "geolocation=(), microphone=(), camera=() always"; add_header Cross-Origin-Opener-Policy same-origin-allow-popups always; add_header Content-Security-Policy " ...
Opening the pop up and communicating complains
The lists are NOT exhaustive. Only what we or Csper.io discovered.
Trusted Types
We should be really safe and start working on getting the UI to work with Trusted Types
Not 100% sure how we'll handle this yet - but we should try to make slow and steady progress.
Apache eCharts
Tooltip writes to the DOM
Stripe
TMLScriptElement src|https://js.stripe.com/v3 HTMLScriptElement src|https://js.stripe.com/v3/fingerprinted/j
LogRocket
This one is weird cause we have it marked in the
script-src
HTMLScriptElement src|https://cdn.logr-ingest.com/logger-1.minGTM
HTMLScriptElement src|https://www.googletagmanager.com/gtm.js?
Monaco
Worker constructor|/static/editor.worker-e9368882.js Worker constructor|/static/json.worker-3dd12af9.js
UNKNOWNS
Given the code around it I think this is Apache eCharts
Cross Origin Opener
We have the header in place but Chrome is still complaining about this. Not 100% sure what it is complaining about
OAuth Providers
Opening the pop up and communicating complains