gbv / login-server

Login and connect accounts with multiple identity providers
https://coli-conc.gbv.de/login/
MIT License
31 stars 32 forks source link

Fix CSP issues #67

Closed stefandesu closed 3 years ago

stefandesu commented 3 years ago

There are still issues with the CSP (Content Security Policy) configuration. If https://coli-conc.gbv.de/login/api is opened in Safari, it shows:

[Error] Refused to connect to wss://coli-conc.gbv.de/login/ because it appears in neither the connect-src directive nor the default-src directive of the Content Security Policy.