4 ms·
Thanks to your post, I learnt about Content-Security-Policy in HTTP headers. I thought, that's awesome, let me add a tight CSP to my site (https://scripter.co h
by kaushalmodi 8y ago
Thanks to your post, I learnt about Content-Security-Policy in HTTP headers. I thought, that's awesome, let me add a tight CSP to my site (https://scripter.co https://scripter.co) as I don't load any content from outside and the only thing going out are Webmentions sending requests... and then I realize that I use #mathjax on some pages..
MathJax requires me to add 'unsafe-inline' and 'unsafe-eval' to script-src, and 'unsafe-inline' style-src. So my overall CSP becomes quite weak :(
Anyone would have an idea how to implement CSP without those, and uses MathJax?
Thanks.
- kaushalmodi 8y agoI fixed this finally, thanks to Github user dpvc and his suggested way of writing MathJax config: https://github.com/mathjax/MathJax/issues/1988#issuecomment-384978927 https://github.com/mathjax/MathJax/issues/1988#issuecomment-....