Skip to content

History / Content Security Policy Hardening

Revisions

  • Add CSP hardening blue-sky page (issue #43) Documents what strict-CSP support would take and why it's a large phased refactor rather than a bug fix: ~1,300 inline handlers + 159 inline script blocks, plus a measured risk assessment (defence-in-depth behind existing output escaping; low-to-moderate urgency for a self-hosted internal app). Also captures the working 'unsafe-inline' policy for today. Linked under Blue sky thinking and cross-referenced from Email Rendering & Images.

    @edmozley edmozley committed Jul 11, 2026