[dokuwiki] Re: Dokuwiki inline scripts violating Content-Security-Policy

  • From: Colin McKinnon <colin.mckinnon@xxxxxxxxx>
  • To: dokuwiki <dokuwiki@xxxxxxxxxxxxx>
  • Date: Tue, 24 Sep 2013 08:52:44 +0100

Hi Moritz,

On 23 September 2013 23:18, Moritz <moritz@xxxxxxxxxxxxxxx> wrote:

> I know I can allow inline scripting, but since
> I host a lot of "untrusted" Dokuwikis by random people, I would rather
> see the scripts being moved into properly linked external JS.
>
>
I'm trying to solve this (and other stuff) with the Jokuwiki plugin. It
also requires changes to the template. See

https://www.dokuwiki.org/plugin:jokuwiki
and
https://www.dokuwiki.org/template:starterpjax

This is still a work in progress - there is a single inline script still
exposed by the template - but the current code is stable.

HTH

C.

Other related posts: