Skip to content
Discussion options

You must be logged in to vote

Thanks for reporting! We made a PR to update the CSP (DuendeSoftware/demo.duendesoftware.com#45) for fonts (and deployed).

As for the sandbox attribute, this is probably defined too wide for the entire IdentityServer deployment here. Looking at why it was originally added was to enable front-channel logout on the Logout.cshtml/LoggedOut.cshtml, where external IdP's logout page can render an iframe.

It's safe to remove this directive in your own app altogether, as you suggest, but may be worth adding origins for your logout pages if front-channel logout is needed there.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by kevin-kallberg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants