nginx: open CSP frame-src from hardcoded domain whitelist to https: scheme-wide

This commit is contained in:
Pontoporeia
2026-07-10 17:26:02 +02:00
parent 6e1d54511d
commit 9965529fd4
2 changed files with 4 additions and 3 deletions
+1
View File
@@ -1,5 +1,6 @@
# TODO
- [x] Open up CSP frame-src from hardcoded domain whitelist to `https:` scheme-wide
- [x] Fix relinked file not appearing in FilePond UI: switch to ID-based input lookup
- [x] Fix student name popover overflowing below viewport: clamp position so popover stays within screen bounds
- [x] Fix orientation (and other filter) metadata links on TFE page leading to empty search: remove redundant `query=` param