Bugless #74
Enable CSP for mastodon
Status:
New
Priority:
Normal
Assignee:
-
Category:
hscloud
Description
Since somewhere around v4.1.4 mastodon recommends adding CSP headers on reverse proxies (see https://github.com/mastodon/mastodon/releases/tag/v4.1.4).
We ignored this during the upgrade (https://gerrit.hackerspace.pl/c/hscloud/+/1691), but we should eventually do it.
Doing this in n-i-c is a bit tedious - it seems the only way is via snippet annotations, which we normally (for good reason) deny in admitomatic, so admitomatic would need to be fixed to allow this.
No data to display