 
      
    | You are here | marcus-obst.de | ||
| | | | | blog.freeradical.zone | |
| | | | | I'm serving Free Radical's images etc. from S3. When I updated to Mastodon v2.1.0, I noticed that all the page's images were missing. Safari's Show JavaScript Console menu revealed a lot of errors like: [Error] Refused to load https://s3-us-west-2.amazonaws.com/freeradical-system/accounts/avatars/000/014/309/static/91f9782fad3f6284.png because it does not appear in the img-src directive of the Content Security Policy. Turns out that some time between the releases of v2.0.0 and v2.1.0, the Mastodon switch... | |
| | | | | localghost.dev | |
| | | | | A guide to cross-site scripting (XSS) attacks and the HTTP Content-Security-Policy header, what it does, how to use it, and how it protects us. | |
| | | | | zacbrown.org | |
| | | | | Zac Brown's Nonsense is the source for all of Zac Brown's nonsense. If it's Zac Brown related, then it's probably nonsense. And if it's nonsense, then it's probably here! | |
| | | | | grayduck.mn | |
| | | Implementing CSP on AMO took six years, but we did it! | ||