Skip to content

Conversation

@hamir-suspect
Copy link
Contributor

📝 Description

Default sandboxing provided by mermaid-js is not compatible with our CSPs since it uses src=data:... to forward the content that should be rendered in the iframe, so we're falling back to secure.

✅ Checklist

  • I have tested this change
  • This change requires documentation update

@hamir-suspect hamir-suspect enabled auto-merge (squash) October 1, 2025 10:03
@hamir-suspect hamir-suspect merged commit 55bd5c0 into main Oct 1, 2025
2 checks passed
@hamir-suspect hamir-suspect deleted the has/csp branch October 1, 2025 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

3 participants