Re: Custom CSP settings

2024-06-16 Thread Lukasz Lenart
pon., 17 cze 2024 o 07:27 Nikhil P Kookkiri napisał(a): > > Hello there, > > The default CSP implementation is allowing inline styles in the JSPs. I am > looking for documentation that will help me use custom CSP settings. Since Struts 6.2.0 you can use CspSettingsAware interface to configure th

Custom CSP settings

2024-06-16 Thread Nikhil P Kookkiri
Hello there, The default CSP implementation is allowing inline styles in the JSPs. I am looking for documentation that will help me use custom CSP settings. Thanks, Nikhil P Kookkiri - To unsubscribe, e-mail: user-unsubscr...@

Re: [EXTERNAL] Re: POP Up Data List Window Struts 6.4 (and 6.3) v 6.1.2.1

2024-06-16 Thread Lukasz Lenart
śr., 12 cze 2024 o 13:14 Nordmeyer, William, E (Serco NA) napisał(a): > Other things we're seeing in developer tools that aren't in the attached logs: > > Content Security Policy blooks inline execution of scripts and stylesheets > The Content Security Policy prevents cross-site scripting attack