> > inline styles are not allowed by our security policy in production
> 
> The `style-src 'self' 'unsafe-inline'` in the CSP header tells me a different 
> story.

OK so it is allowed for views with a map. I'm note sure why that is offhand but 
our goal is to not have it so we don't add new inline styles ourselves but we 
sometimes have to allow it for third party components.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/openstreetmap/openstreetmap-website/pull/5396#issuecomment-2539951659
You are receiving this because you are subscribed to this thread.

Message ID: 
<openstreetmap/openstreetmap-website/pull/5396/c2539951...@github.com>
_______________________________________________
rails-dev mailing list
rails-dev@openstreetmap.org
https://lists.openstreetmap.org/listinfo/rails-dev

Reply via email to