Use a more precise Sourcegraph URL in CSP
Allowing the entire sourcegraph instanc creates a possibility for CSP bypass as it's possible to host arbitrary javascript on sourcegraph. This change restricts the allowed sourcegraph URLs to the api Changelog: security
Showing
Please register or sign in to comment