Skip to content

[lightbox-gallery] Plug-in forces enabling script-src unsafe-inline in CSP. #471

@Eihrister

Description

@Eihrister

Hello!

Trying to clean up my Content-Security-Policy header from unsafe stuff, I found that this plug-in inserts in-line scripting into pages.
This results in me being forced to add "unsafe-inline" to the "script-src".

If it's not too much trouble, I'd prefer it if the code could be moved to a seperate .js file instead :)

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions