Commit Graph

49 Commits

Author SHA1 Message Date
GitLab Bot ca4942bdc4 Add latest changes from gitlab-org/gitlab@master 2025-07-04 12:12:34 +00:00
GitLab Bot f16d40013b Add latest changes from gitlab-org/gitlab@master 2025-06-06 18:12:15 +00:00
GitLab Bot 25ee58e1b8 Add latest changes from gitlab-org/gitlab@master 2025-05-28 18:07:44 +00:00
GitLab Bot 39b47b75cf Add latest changes from gitlab-org/gitlab@master 2024-04-24 18:10:01 +00:00
GitLab Bot bef0a53775 Add latest changes from gitlab-org/gitlab@master 2024-04-24 00:17:05 +00:00
GitLab Bot cc310f2111 Add latest changes from gitlab-org/gitlab@master 2024-03-27 12:12:31 +00:00
GitLab Bot 91a8a89bd6 Add latest changes from gitlab-org/gitlab@master 2024-03-21 15:10:36 +00:00
GitLab Bot bb0d99269b Add latest changes from gitlab-org/gitlab@master 2023-12-08 18:14:31 +00:00
GitLab Bot 91145d427b Add latest changes from gitlab-org/gitlab@master 2023-10-05 21:11:33 +00:00
GitLab Bot e33402e375 Add latest changes from gitlab-org/gitlab@master 2023-08-31 18:09:40 +00:00
GitLab Bot 8d98d0dd3a Add latest changes from gitlab-org/gitlab@master 2023-08-24 15:08:26 +00:00
GitLab Bot 7c5f1bfac7 Add latest changes from gitlab-org/gitlab@master 2023-07-28 18:11:01 +00:00
GitLab Bot 9979d2afd6 Add latest changes from gitlab-org/gitlab@master 2023-07-27 15:10:15 +00:00
GitLab Bot 0e0df204c1 Add latest changes from gitlab-org/gitlab@master 2023-05-10 12:09:12 +00:00
GitLab Bot 248492cc57 Add latest changes from gitlab-org/gitlab@master 2023-03-21 18:15:17 +00:00
GitLab Bot 06af519348 Add latest changes from gitlab-org/gitlab@master 2023-03-09 06:12:08 +00:00
GitLab Bot 75d101a1c2 Add latest changes from gitlab-org/gitlab@master 2023-01-18 21:10:01 +00:00
GitLab Bot 7fe1490a58 Add latest changes from gitlab-org/gitlab@master 2022-11-29 18:09:26 +00:00
GitLab Bot 983f6954d1 Add latest changes from gitlab-org/gitlab@master 2022-11-02 18:10:05 +00:00
GitLab Bot 30b8ea126f Add latest changes from gitlab-org/gitlab@master 2022-10-31 18:09:25 +00:00
GitLab Bot 953b58d061 Add latest changes from gitlab-org/gitlab@master 2022-07-11 09:08:40 +00:00
GitLab Bot eddf359962 Add latest changes from gitlab-org/gitlab@master 2022-06-30 03:08:59 +00:00
GitLab Bot 3fbfc0075a Add latest changes from gitlab-org/gitlab@master 2022-05-19 09:09:08 +00:00
GitLab Bot 91c2554bcf Add latest changes from gitlab-org/gitlab@master 2022-05-17 09:08:20 +00:00
GitLab Bot 9b762f50fe Add latest changes from gitlab-org/gitlab@master 2022-04-14 15:08:59 +00:00
GitLab Bot f6f4bc2bc0 Add latest changes from gitlab-org/gitlab@master 2022-04-07 09:08:40 +00:00
GitLab Bot 20b517258a Add latest changes from gitlab-org/gitlab@master 2022-02-18 03:17:36 +00:00
GitLab Bot a8281ac434 Add latest changes from gitlab-org/gitlab@master 2022-01-11 15:15:55 +00:00
GitLab Bot 16d8ebae46 Add latest changes from gitlab-org/gitlab@master 2021-11-30 21:10:33 +00:00
GitLab Bot 77b8390171 Add latest changes from gitlab-org/gitlab@master 2021-11-24 12:10:21 +00:00
GitLab Bot b563a5209a Add latest changes from gitlab-org/gitlab@master 2021-11-23 09:10:20 +00:00
GitLab Bot 11c2b8eff6 Add latest changes from gitlab-org/gitlab@master 2021-11-11 18:14:04 +00:00
GitLab Bot a056c4d05f Add latest changes from gitlab-org/gitlab@master 2021-10-29 09:10:11 +00:00
GitLab Bot 45760607bc Add latest changes from gitlab-org/gitlab@master 2021-10-25 09:12:21 +00:00
GitLab Bot b428f0ed8d Add latest changes from gitlab-org/gitlab@master 2021-10-21 21:14:18 +00:00
GitLab Bot ee2c09733d Add latest changes from gitlab-org/gitlab@master 2021-10-19 18:13:24 +00:00
GitLab Bot 30e5ae4c2b Add latest changes from gitlab-org/gitlab@master 2021-10-06 18:12:19 +00:00
GitLab Bot 79ecd9a748 Add latest changes from gitlab-org/gitlab@master 2021-08-13 21:09:54 +00:00
GitLab Bot e6de69cc2e Add latest changes from gitlab-org/gitlab@master 2021-08-12 03:10:11 +00:00
GitLab Bot caff5659c9 Add latest changes from gitlab-org/gitlab@master 2021-08-10 21:10:06 +00:00
GitLab Bot 7c28a67789 Add latest changes from gitlab-org/gitlab@master 2021-06-30 12:07:58 +00:00
GitLab Bot 4f41b713eb Add latest changes from gitlab-org/gitlab@master 2021-06-03 15:10:01 +00:00
GitLab Bot e5f1831403 Add latest changes from gitlab-org/gitlab@master 2021-06-03 09:10:18 +00:00
GitLab Bot 685084aaf4 Add latest changes from gitlab-org/gitlab@master 2021-06-03 06:10:07 +00:00
GitLab Bot 8c438dd7a6 Add latest changes from gitlab-org/gitlab@master 2021-06-01 12:09:36 +00:00
GitLab Bot c0bc55ffe1 Add latest changes from gitlab-org/gitlab@master 2021-05-25 21:10:26 +00:00
GitLab Bot c33a9adb70 Add latest changes from gitlab-org/gitlab@master 2021-05-11 12:10:20 +00:00
Stan Hu d265408c26 Add missing report-uri to CSP config
This is supported in Rails 5.2, although it may be
deprecated in the future by reports-to.
2019-08-07 11:21:08 -07:00
Stan Hu 5fbbd3dd6e
Add support for Content-Security-Policy
A nonce-based Content-Security-Policy thwarts XSS attacks by allowing
inline JavaScript to execute if the script nonce matches the header
value. Rails 5.2 supports nonce-based Content-Security-Policy headers,
so provide configuration to enable this and make it work.

To support this, we need to change all `:javascript` HAML filters to the
following form:

```
= javascript_tag nonce: true do
  :plain
    ...
```

We use `%script` throughout our HAML to store JSON and other text, but
since this doesn't execute, browsers don't appear to block this content
from being used and require the nonce value to be present.
2019-08-07 12:37:31 +10:00