Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Configure GovukContentSecurityPolicy for govuk_app_config changes
This configures the content security policy in preparation for the breaking changes coming from alphagov/govuk_app_config#279. As this app uses govuk_admin_template and that uses jQuery 1.x and inline script tags, then this app needs unsafe_inline for script and the nonce generator disabled. As an aside, It was a surprise that this application had configured the GovukContentSecurityPolicy as this had been initially done just in Frontend apps and it looks like this made it through in some outsourced Rails updates [1]. I'm leaving this config in so there is an example of an app outside of frontend using it to build on and as a case study in configuring an app. [1]: 45a5a51
- Loading branch information