potiuk commented on PR #1353: URL: https://github.com/apache/airflow-site/pull/1353#issuecomment-3693911771
> > I think we do not need that (And should not have it). CSP is added automatically by ASF hosting. > > We should not override the headers. See https://infra.apache.org/tools/csp.html , also #1255 > > Interesting, wasn't aware of that - thanks! My browser still complains though (some of the fonts aren't rendered properly) We should then embed those fonts in our page. The problem is that if we need fonts to be downloaded from somewhere (say google) - in order to render the page - this is Privacy concern that we don't want to deal with. Similarly I embedded screenshots from youtube videos to be served from our page rather than from youtube.com -> user needs to explicitly click on those to be redirected to youtube page, but there is no privacy tracking when they just view our page. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
