Skip to content

Support Subresource Integrity #3

Description

@atjn

EWAB should automatically detect any scripts and styles that are included in a document, and produce integrity hashes for them.

If the scripts are inline, their hashes will need to be served in HTTP CSP headers, and since EWAB doesn't handle headers, the best it can do is output the hashes in a standardized format that the developer can then plug into the server.

This is not just an added security feature. EWAB uses custom elements with inline styles for several UI components, and that means you have to set unsafe-inline in the CSP header to make the components work :( Using EWAB shouldn't require you to downgrade security.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions