-
-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Open
Labels
Description
There are a number of onclick attributes that have inline javascript: https://github.com/search?q=repo%3Apallets-eco%2Fflask-admin%20onclick&type=code
These don't support CSP nonces and so may be blocked in applications that apply strict CSP rules.
We should migrate all of the onclick attributes to event listeners set up in some JS files.
See also "Refactor inline event handlers and javascript: URIs" of https://csp.withgoogle.com/docs/adopting-csp.html
marcsello