-
Improvement
-
Resolution: Unresolved
-
Minor
editor/editor-debug.js and simpleeditor-debug.js have inline JavaScript.
We need to check for uses of it.
Culprit
- editor/editor-debug.js#L5157
- editor/editor-min.js#L18
- editor/simpleeditor-debug.js#L5157
- editor/simpleeditor-min.js#L18
Proposal
https://www.jenkins.io/doc/developer/security/csp/#inline-event-handlers