FastAPI: use internal typeahead and remove jquery

Awesome!

Signed-off-by: Kevin Morris <kevr@0cost.org>
This commit is contained in:
Kevin Morris 2021-06-29 22:44:41 -07:00
parent 2835dd89ea
commit 3a74f76ff9
6 changed files with 20 additions and 35 deletions

View file

@ -83,10 +83,7 @@ async def add_security_headers(request: Request, call_next: typing.Callable):
# Add CSP header.
nonce = request.user.nonce
csp = "default-src 'self'; "
script_hosts = [
"ajax.googleapis.com",
"cdn.jsdelivr.net"
]
script_hosts = []
csp += f"script-src 'self' 'nonce-{nonce}' " + ' '.join(script_hosts)
# It's fine if css is inlined.
csp += "; style-src 'self' 'unsafe-inline'"