Comments (2)
Hey @aduth, thanks for this and many apologies for taking so long to reply.
I have to say my knowledge of CSPs is still pretty limited (despite your help in #202) but what you are suggesting makes total sense.
My gut reaction is to go down the preview_embeds.frame_ancestors
config option route as I still feel that keeping parity with the way that ViewComponent disables the CSP is probably still preferable. I'm also a little nervous about adding more complex policy configuration code when I don't feel like I have a lot of expertise in this area.
I'm pretty short of time for working on Lookbook at the moment but I'll try to have a proper think about this as soon as I can. As the config option route is probably simpler I may see if I can give that a go - I'll let you know once I have any code ready so you can take a look at it and see if it will work for you.
from lookbook.
Hi @allmarkedup, totally understand if you don't have the bandwidth for this at the moment! Fortunately our workaround is serving us just fine for the time being, but we'll look forward to this functionality being supported out of the box. Happy to review or provide feedback for any changes or ideas you come up with.
from lookbook.
Related Issues (20)
- Add the ability to hide a nested within a group. HOT 3
- Cannot choose display options in an embedded preview HOT 4
- Support better errors / web console instead of rescuing errors in Lookbook HOT 2
- undefined method `strftime' for nil:NilClass with nil datetime HOT 1
- Hidden scenarios within groups are not accessible via their URL
- Swap the order of Previews and Pages sections HOT 4
- Ability to search within pages section HOT 3
- X-Frame-Options always set to deny HOT 8
- Can't draw templates that require instance variables HOT 5
- Lookbook overrides ViewComponent `show_previews` config depending on load order HOT 3
- ActionView::Template::Error occurs when trying to render a template file with a partial HOT 5
- FEA: Support for Mailer Previews HOT 1
- Documentation request: mention support for Phlex in the README HOT 5
- Previews not rendering nested components HOT 2
- Better integration with Phlex HOT 1
- Version requirement for listen gem is not specified, and wrong version error is suppressed HOT 1
- Syntax error reporting in Lookbook HOT 2
- Sharing View Component Previews Across Multiple Projects Without Duplicating Files
- Enlarge search field clear button
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from lookbook.