We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent d71efa9 commit cab754dCopy full SHA for cab754d
src/ConfluenceContentProvider.ts
@@ -44,10 +44,14 @@ export class ConfluenceContentProvider implements vscode.TextDocumentContentProv
44
let body = await parseMarkup(unpackConfluenceUri(uri), document.getText());
45
let cssLink = cssUri("confluence.css");
46
47
+
48
+ // Security
49
+ // https://code.visualstudio.com/api/extension-guides/webview#security
50
return `<!DOCTYPE html>
51
<html>
52
<head>
53
<meta http-equiv="Content-type" content="text/html;charset=UTF-8">
54
+ <meta http-equiv="Content-Security-Policy" content="default-src 'none'; img-src vscode-resource: https:; script-src vscode-resource:; style-src vscode-resource:;"/>
55
<link rel="stylesheet" href="${cssLink}">
56
</head>
57
<body>
0 commit comments