Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security risk: Prismic toolbar sharable link loads third party html2canvas script #102

Open
dkhuntrods opened this issue Sep 21, 2022 · 0 comments

Comments

@dkhuntrods
Copy link

Hi there,
We're concerned about the Prismic toolbar loading the third-party html2canvas script directly.
Should this url ever be compromised it would present a huge security risk. We've had to add it to our CSP but it's far from ideal.
Ideally, Prismic would mirror it and self-host, or provide a way to configure or override the source for end users to self-host.
Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant