Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: add icp-api.io to default CSP; default to allow raw access #3327

Merged
merged 14 commits into from
Aug 26, 2023

Conversation

ericswanson-dfinity
Copy link
Member

Description

  1. Make redirects from raw to non-raw opt-in, rather than opt-out. The default allow_raw_access setting for assets is now true, rather than false. This is in part because webviews on iOS and Android don't handle service workers very well.

  2. Added https://icp-api.io to the default Content-Security-Policy header.

Fixes # (issue)

How Has This Been Tested?

Checklist:

  • The title of this PR complies with Conventional Commits.
  • I have edited the CHANGELOG accordingly.
  • I have made corresponding changes to the documentation.

@ericswanson-dfinity ericswanson-dfinity requested a review from a team as a code owner August 25, 2023 17:34
@ericswanson-dfinity ericswanson-dfinity changed the title fix: add icp0-api.io to default CSP; default to allow raw access fix: add icp-api.io to default CSP; default to allow raw access Aug 25, 2023
@ericswanson-dfinity ericswanson-dfinity merged commit 6d7422a into release-0.14.3 Aug 26, 2023
@ericswanson-dfinity ericswanson-dfinity deleted the raw-access-icp-api.io-0.14.3 branch August 26, 2023 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant