Mise en ligne
A Content-Security-Policy, with a separate one for your HTML
Every page of the platform now carries a Content-Security-Policy with a per-request nonce. Trial sites and sites on their own domain get a different, closed policy: your HTML runs in its own sandbox and can never borrow a script permission from ours. The template preview also moved server-side, so the preview frame gets the same policy as the real site.
Mis en ligne avec le commit 229d4df