View Issue Details

IDProjectCategoryView StatusLast Update
0001283savapage-server[All Projects] Securitypublic2025-01-21 14:18
ReporterrijkrAssigned Torijkr 
PrioritynormalSeveritymajorReproducibilityalways
Status assignedResolutionopen 
Product Version1.5.0 
Target VersionFixed in Version 
Summary0001283: Make WebApp CSP compliant
DescriptionIST: Wicket 9.x introduced a Content Security Policy (CSP) that is active by default and prevents inline JavaScript and CSS code from been executed. SavaPage does not comply to CSP. As a result WebApp UI is completely scrambled. For now, this policy is disabled in Wicket.
SOLL: Comply to CSP.
Additional Informationhttps://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-01-21 14:18 rijkr New Issue
2025-01-21 14:18 rijkr Status new => assigned
2025-01-21 14:18 rijkr Assigned To => rijkr