#5813 - Potentially risky wildcard default-src CSP set on several pages

This is a spacer post for a website comment topic. The content this topic relates to: #5813 - Potentially risky wildcard default-src CSP set on several pages
Automated message: This issue was created using the Report Issue Wizard on the Composr homesite.
Possible this may be because of "Permit no JavaScript nonce for injected scripts", which honestly should be disabled by default IMO and users instructed to enable it only if they must for third-party libraries that need it.
This seems to be happening on a lot of the add and edit screens. Other screens have the proper headers.
This was mainly a WYSIWYG issue, fixed in 11 beta2, but I still see it on some other screens. Leaving the issue open for now.
0 guests and 0 members have recently viewed this.