Skip to content

Secure textbook previews by isolating inline scripts from main domain CSP #27

Description

@harsharajkumar-273

Helmet CSP is currently disabled in server.ts because PreTeXt compiles require inline scripts. We should isolate the preview to prevent XSS risks, perhaps by using a separate sandboxed subdomain or a stricter iframe sandbox configuration.

Metadata

Metadata

Assignees

Labels

ADVENTURERIntermediate (25 pts)ELUSOCRequired Tracking

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions