Feature: Trusted Types support (#64975)
* Draft: Feature: Trusted Types support * remove trusted-types package * Create policy before jQuery and Angular is loaded and add feature flag * Add trustedTypePolicies * Sanitize scriptURL * Add TT meta tag for test env * Move trusted types into core * Add DOMParser support for TrustedHTML * Seperate RSS sanitization and add better TrustedHTML support * Get test CSP header from config * Remove dompurify dep from core * Add documentation for trusted types * Apply suggestions from code review Co-authored-by: Kristian Bremberg <114284895+KristianGrafana@users.noreply.github.com> * Add comment about Github discussion thread and things breaking * Remove changes from News panel * Remove TT feature toggle * Expose TT and CSPReportOnly to frontend * Log errors in console when CSP report only is enabled * Log error for reporting and remove test mode * Only insert CSP header in HTML for dev env * Update docs --------- Co-authored-by: Tobias Skarhed <tobias.skarhed@gmail.com> Co-authored-by: Tobias Skarhed <1438972+tskarhed@users.noreply.github.com>
This commit is contained in:
co-authored by
Tobias Skarhed
Tobias Skarhed
parent
278a8fccc9
commit
35407142d0
+1
-1
@@ -120,7 +120,6 @@
|
||||
"@types/d3-force": "^3.0.0",
|
||||
"@types/d3-scale-chromatic": "3.0.0",
|
||||
"@types/debounce-promise": "3.1.6",
|
||||
"@types/dompurify": "^2",
|
||||
"@types/eslint": "8.21.1",
|
||||
"@types/file-saver": "2.0.5",
|
||||
"@types/glob": "^8.0.0",
|
||||
@@ -293,6 +292,7 @@
|
||||
"@sentry/utils": "6.19.7",
|
||||
"@testing-library/react-hooks": "^8.0.1",
|
||||
"@types/react-resizable": "3.0.3",
|
||||
"@types/trusted-types": "2.0.3",
|
||||
"@types/webpack-env": "1.18.0",
|
||||
"@visx/event": "3.0.1",
|
||||
"@visx/gradient": "3.0.0",
|
||||
|
||||
Reference in New Issue
Block a user