JDownloader Community - Appwork GmbH
 

Reply
 
Thread Tools Display Modes
  #1  
Old 06.01.2018, 12:08
narcolepticinsomniac
Guest
 
Posts: n/a
Default CSP for this site is pretty ridiculous

Blocking data-images? Really? What does this accomplish besides being annoying? I use custom scrollbars and it took me a minute to figure out why my scrollbars have no arrows here. Talk about overkill.
Reply With Quote
  #2  
Old 06.01.2018, 16:01
raztoki's Avatar
raztoki raztoki is offline
English Supporter
 
Join Date: Apr 2010
Location: Australia
Posts: 17,614
Default

What exactly is the problem?
__________________
raztoki @ jDownloader reporter/developer
http://svn.jdownloader.org/users/170

Don't fight the system, use it to your advantage. :]
Reply With Quote
  #3  
Old 07.01.2018, 02:13
narcolepticinsomniac
Guest
 
Posts: n/a
Default

Content Security Policy of this site. It's not crazy abnormal for sites to block images hosted on other domains for security purposes (although it's usually sites like Github, not forums). jdownloader.org however, has a modified CSP which blocks data-images (like arrows in custom scrollbars). There is no security benefit to blocking data-images, it's just annoying. This is the only site I've ever seen do it, because it's a ridiculous thing to do.
Reply With Quote
  #4  
Old 07.01.2018, 02:37
raztoki's Avatar
raztoki raztoki is offline
English Supporter
 
Join Date: Apr 2010
Location: Australia
Posts: 17,614
Default

Guess need to wait for Jiaz to respond about that, as I really only help run the forum not the setup security side.

In the scheme of things its not the end of the world.
__________________
raztoki @ jDownloader reporter/developer
http://svn.jdownloader.org/users/170

Don't fight the system, use it to your advantage. :]
Reply With Quote
  #5  
Old 16.01.2018, 17:05
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,532
Default

Can you please tell me what browser/extension you use to customize scrollbars. Then I will look into it and modify csp to make it work again.
__________________
JD-Dev & Server-Admin
Reply With Quote
  #6  
Old 02.02.2018, 08:59
narcolepticinsomniac
Guest
 
Posts: n/a
Default

https://chrome.google.com/webstore/d...kjfobafhncgmne

**External links are only visible to Support Staff****External links are only visible to Support Staff**

Sorry for the delay, I didn't get a notification. I just don't get how blocking data-images improves security. He's right, in the scheme of things it's not the end of the world, but it seems unnecessary.
Reply With Quote
  #7  
Old 02.02.2018, 09:02
narcolepticinsomniac
Guest
 
Posts: n/a
Default

External links are only visible to supporters. Also genius. Presumably you can see it.
Reply With Quote
  #8  
Old 05.02.2018, 17:08
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,532
Default

I will check/update CSP as soon as I find time for it

Links are whitelisted. Non whitelisted links are only visible to support staff members
__________________
JD-Dev & Server-Admin
Reply With Quote
  #9  
Old 16.02.2018, 13:36
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,532
Default

Should be working now
__________________
JD-Dev & Server-Admin
Reply With Quote
  #10  
Old 21.02.2018, 11:24
narcolepticinsomniac
Guest
 
Posts: n/a
Default

Yup. Much better!
Reply With Quote
  #11  
Old 21.02.2018, 11:45
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,532
Default

Thanks for the feedback! sorry for the inconvenience
__________________
JD-Dev & Server-Admin
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT +2. The time now is 05:32.
Provided By AppWork GmbH | Privacy | Imprint
Parts of the Design are used from Kirsch designed by Andrew & Austin
Powered by vBulletin® Version 3.8.10 Beta 1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.