Ruben Fiszel
c0b87cc7d7
send a webhook on new user + lazy static refactor ( #1203 )
...
* supercharge
* supercharge
* progress
* progress
* display config
* display config
* display config
* display config
* fix extensions
* fix build
* disable nsjail = false for test
2023-02-15 10:59:50 +01:00
Ruben Fiszel
c0df9a5e20
update axum
2023-01-11 08:19:20 +01:00
Ruben Fiszel
2484f15a79
menu redesign
2022-11-15 11:57:05 +01:00
Jakub Kołodziejczak
e08ca0423c
refactor(backend): improve memory footprint related to csp ( #866 )
2022-11-07 01:29:37 +01:00
Jakub Kołodziejczak
3333713644
chore(backend): set csp based on env var ( #864 )
...
* chore(backend): set csp based on env var
* use extension instead of reading directly from env var
2022-11-06 22:35:37 +01:00
Jakub Kołodziejczak
209dee7bd8
chore(csp): fix trailing semicolon ( #863 )
2022-11-06 19:50:45 +01:00
Jakub Kołodziejczak
3ba18700de
fix(backend): improve csp ( #861 )
...
rationale for setting `'unsafe-inline'` is that it cannot be more void
than the lack of `script-src` but it still might add some benefits
2022-11-06 18:00:16 +01:00
Jakub Kołodziejczak
7040bbe4c9
fix(backend): tighten http security headers ( #860 )
...
* fix(backend): set http security headers (vol.1)
* (vol.2) minimal *working* content security policy
* (vol.3) set csp only if https and if hosted on cloud
* improve generics
* get CLOUD_HOSTED from extension
* remove X-XSS-Protection
rationale as per: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
* conditionally set all security related http headers
2022-11-06 17:07:25 +01:00
Kai Jellinghaus
0034129a30
restructure the entire backend layout using workspaces ( #815 )
2022-10-29 11:58:06 +02:00