Skip to content

Configurable upgrade-insecure-requests in CSP for FrameBlobBuider#252

Description

@aaronleopold

Hey 馃憢

I develop and maintain software that uses Readium and believe this issue is a result of upgrade-insecure-requests being unconditionally added to the security policy on the frame. I made a tentative fix on a fork that makes it conditional via a new config upgradeInsecureRequests that passes it down, but wanted to open an issue before assuming the change would be welcome in a PR. The default should preserve the current behavior (always upgrade).

This seems related-ish to #120, though the referenced code snippet there is what I see on the develop branch so maybe that one is already resolved.

Thank you for all the work across all the Readium toolkits!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions