Thread: content security protocol and bootstrap

    content security protocol and bootstrap


    I have implemented CSP to block all inline scripts (to prevent e.d. XSS) but something in the jquery bootstrap which is linked to and needs gets blocked. Apparently, it is an onfocusin. I think it is used inline because CSP specifically blocks that.
    How can I solve this?

    thanks, Anjo

    the error message I am getting (unfortunately in dutch but I think it is understandable) is:
    Content Security Policy: De instellingen van de pagina blokkeerden het laden van een bron op self (‘script-src’). Source: onfocusin attribute on DIV element.
