fix: recipe config cleanup, report-only CSP, logout redirect validation (#6124)

This commit is contained in:
Alireza authored and GitHub committed 2026-07-07 13:18:46 -04:00
1 parent 973631b7e8
commit f8546ce0e0
27 files changed
+446 -75

No files matched your search

+8
View File
@@ -24,6 +24,14 @@
X-Frame-Options = "DENY"
X-XSS-Protection = "1; mode=block"
# Report-Only CSP: observational only, enforces nothing. Watch browser
# consoles for violation reports before ever promoting this to an
# enforcing Content-Security-Policy header. cdnjs.cloudflare.com is for
# the Rollbar snippet in html-templates/rollbar.html (demo builds);
# connect-src stays broad because deployments point the viewer at
# arbitrary DICOMweb origins.
Content-Security-Policy-Report-Only = "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https: blob:; worker-src 'self' blob:; object-src 'self' blob:; frame-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'"
cache-control = '''
max-age=0,
no-cache,