Content Security Policy

From annawiki

PDF in Chrome

https://bugs.chromium.org/p/chromium/issues/detail?id=271452

object-source:none and PDF will not be shown in Chrome

SVG

form-action

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/form-action

Redirect blocking - will disturb MediaWiki page reading after submitting a change

  • Firefox 57 doesn't block
  • Chrome 63 does block

MediaWiki

Failing on simple lists, no bullet points shown:

  • line one
  • line two

form-action - Chrome blocks redirect after text edit