Jump to content

Recommended Posts

Posted
  On 9/17/2016 at 6:06 PM, Licensecart said:

Yep :) I prefer the CDN myself since we can just edit the version.

Expand  

Yep. Equally very simple... and I just realized that's why my Blesta install looked so fucked with Content-Security-Policy enabled... I forgot to whitelist the CDN...

Well... that will be fixed later. But it's likely something to watch out for as people start implementing Content-Security-Policy. Something to note in the docs, maybe?

Posted
  On 9/17/2016 at 6:10 PM, Keiro said:

Yep. Equally very simple... and I just realized that's why my Blesta install looked so fucked with Content-Security-Policy enabled... I forgot to whitelist the CDN...

Well... that will be fixed later. But it's likely something to watch out for as people start implementing Content-Security-Policy. Something to note in the docs, maybe?

Expand  

Never heard of it.... what is it? I use HSTS but via the Apache profile.

Posted
  On 9/17/2016 at 6:11 PM, Licensecart said:

Never heard of it.... what is it? I use HSTS but via the Apache profile.

Expand  

New security measure that helps browsers load stuff ONLY whitelisted by your content-security policy. The link I included in my previous post should help with understanding this in-depth. You can see this for yourself with https://securityheaders.io/?q=https://eidolonhost.com/

It's still a bit of a work in progress, fine-tuning my CSP policy for the server.

  • 1 month later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...