aboutsummaryrefslogtreecommitdiffstats
path: root/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt
Commit message (Expand)AuthorAgeFilesLines
* Add the ability to set the CSP nonce only to the specified directivesyuuji.yaginuma2019-06-221-0/+3
* Revert "Revert "Merge pull request #34387 from yhirano55/rails_info_propertie...Kasper Timm Hansen2019-01-081-0/+4
* Revert "Merge pull request #34387 from yhirano55/rails_info_properties_json"Kasper Timm Hansen2019-01-081-4/+0
* Add `connect_src` example to content security policy initializeryuuji.yaginuma2018-11-041-0/+4
* [ci skip] Spell out the full variable in generated code.Kasper Timm Hansen2018-02-241-1/+1
* Correctly set `content_security_policy_nonce_generator`yuuji.yaginuma2018-02-241-1/+1
* Add support for automatic nonce generation for Rails UJSAndrew White2018-02-191-1/+4
* Disable CSP by defaultRafael Mendonça França2018-01-301-10/+10
* Use unsafe_inline as the default for script_src CSP until we get a nonce alte...David Heinemeier Hansson2018-01-121-1/+1
* Add note about having to restart when modifying initializerDavid Heinemeier Hansson2018-01-121-0/+2
* Use complete variable names rather than single-letter abbreviations for styleDavid Heinemeier Hansson2018-01-121-8/+8
* Add DSL for configuring Content-Security-Policy headerAndrew White2017-11-271-0/+20