Refactor build and CSP headers for Safari compat (#1442)

* add unsafe-inline directive to style-src

* debugging - turn on csp reporting

* revert reporting only csp

* do not inline JS and CSS in build

* enable HTTPs only when in production mode

* remove debug printf

* fix clean target

* revert force_https removal
This commit is contained in:
Bruce Martin
2020-05-04 12:47:35 -07:00
committed by GitHub
parent 6cccc41c0f
commit f42f5151a6
7 changed files with 1340 additions and 42 deletions
+5 -4
View File
@@ -52,10 +52,11 @@
<div id="root"></div>
{% for script in SCRIPTS %}
<script type="text/javascript" src="{{script | safe}}"></script>
{% endfor %} {% for ils in INLINE_SCRIPTS %}
<script type="text/javascript">
{% include ils %}
</script>
{% endfor %}
{% for ils in INLINE_SCRIPTS %}
<!-- caution: do not change white space in this script element -->
<script type="text/javascript" no-csp-hash>{% include ils %}</script>
{% endfor %}
</body>
</html>