From 0485177282b44a6f0b1af4bae5f5b86ad634f099 Mon Sep 17 00:00:00 2001 From: PJ Date: Mon, 22 Jun 2026 13:35:09 -0400 Subject: [PATCH] chore(security): restrictive content security policy security.csp was null (no CSP). Add a restrictive policy as defense-in-depth: self-only by default, data:/blob: images for cover and figure URLs, inline styles for React/inline style attributes, and blob: workers for pdf.js. Needs verification against a production build (covers, preview, export, IPC). Claude-Session: https://claude.ai/code/session_01RzTWrLiy4zGuw2hZSQGamk --- src-tauri/tauri.conf.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src-tauri/tauri.conf.json b/src-tauri/tauri.conf.json index 5d3bafb..b2da513 100644 --- a/src-tauri/tauri.conf.json +++ b/src-tauri/tauri.conf.json @@ -21,7 +21,7 @@ } ], "security": { - "csp": null + "csp": "default-src 'self'; img-src 'self' data: blob:; font-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self'; worker-src 'self' blob:; connect-src 'self' ipc: http://ipc.localhost" } }, "bundle": {