• dcouture's avatar
    Use a more precise Sourcegraph URL in CSP · 29399b2e
    dcouture authored
    Allowing the entire sourcegraph instanc creates
    a possibility for CSP bypass as it's possible to host
    arbitrary javascript on sourcegraph. This change
    restricts the allowed sourcegraph URLs to the api
    
    Changelog: security
    29399b2e
sourcegraph_decorator.rb 1.1 KB