From dd515c80ca12a03c63062b5ec73d85ea79996a6b Mon Sep 17 00:00:00 2001 From: tiddlygit-test Date: Tue, 9 Nov 2021 00:48:31 +0800 Subject: [PATCH] chore: disable useless csp --- src/services/windows/index.ts | 4 ++-- webpack.plugins.js | 32 ++++++++++++++++---------------- 2 files changed, 18 insertions(+), 18 deletions(-) diff --git a/src/services/windows/index.ts b/src/services/windows/index.ts index 595341f7..1ad1a311 100644 --- a/src/services/windows/index.ts +++ b/src/services/windows/index.ts @@ -147,8 +147,8 @@ export class Window implements IWindowService { devTools: !isTest, nodeIntegration: false, nativeWindowOpen: true, - webSecurity: !isDevelopmentOrTest, - allowRunningInsecureContent: false, + webSecurity: false, + allowRunningInsecureContent: true, contextIsolation: true, preload: MAIN_WINDOW_PRELOAD_WEBPACK_ENTRY, additionalArguments: [ diff --git a/webpack.plugins.js b/webpack.plugins.js index feecea92..becd2833 100644 --- a/webpack.plugins.js +++ b/webpack.plugins.js @@ -60,22 +60,22 @@ exports.renderer = _.compact([ 'process.env.NODE_ENV': `"${process.env.NODE_ENV ?? 'production'}"`, // global: {}, }), - new CspHtmlWebpackPlugin( - { - 'base-uri': ["'self'"], - 'object-src': ["'none'"], - 'script-src': ["'self' 'unsafe-eval'"], - 'style-src': ["'self' 'unsafe-inline'"], - 'frame-src': ["'none'"], - 'worker-src': ["'none'"], - 'connect-src': ['https://api.github.com https://tiddlygit-desktop.authing.cn ws://localhost:3000'], - }, - { - nonceEnabled: { - 'style-src': false, - }, - }, - ), + // new CspHtmlWebpackPlugin( + // { + // 'base-uri': ["'self'"], + // 'object-src': ["'none'"], + // 'script-src': ["'self' 'unsafe-eval'"], + // 'style-src': ["'self' 'unsafe-inline'"], + // 'frame-src': ["'none'"], + // 'worker-src': ["'none'"], + // 'connect-src': ['https://api.github.com https://tiddlygit-desktop.authing.cn ws://localhost:3000'], + // }, + // { + // nonceEnabled: { + // 'style-src': false, + // }, + // }, + // ), process.env.NODE_ENV === 'production' ? undefined : new WebpackBar(), process.env.NODE_ENV === 'production' ? // eslint-disable-next-line @typescript-eslint/no-unsafe-call