documentation/content/administration
Julien Castiaux 508a324bc0 [FIX] deploy: set Content-Security-Policy on static
The Content-Security-Policy[^1] http header was only set on the response
generated by controllers but it was missing from the `/<module>/static/`
route.

It is not strictly necessary to set that header on the responses comming
from that routes as it is not possible to add new static files or edit
existing ones via the interface (not even as admin). Only the developers
and system administrator can access those files.

It is also worth mentionning that using the Odoo internal web server to
deliver static files is suboptimal. Outside of a dev environment, those
files will typically be delivered via a web server[^2] and sysadmins
should configure their web server to set the CSP header on static images.

[^1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
[^2]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments

closes odoo/documentation#6952

X-original-commit: f3f44fe5f2
Related: odoo/odoo#146588
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
2023-12-18 22:48:47 +00:00
..
install [FIX] deploy: set Content-Security-Policy on static 2023-12-18 22:48:47 +00:00
maintain [IMP] upgrade: overhaul upgrade doc 2023-11-07 15:48:49 +00:00
odoo_sh [IMP] upgrade: overhaul upgrade doc 2023-11-07 15:48:49 +00:00
upgrade [IMP] upgrade: overhaul upgrade doc 2023-11-07 15:48:49 +00:00
install.rst [REF] install: move intro to main install page and split by install type 2023-08-18 16:16:12 +02:00
maintain.rst [FW][ADD] maintain: connect office365 with azure oauth 2023-01-18 17:38:17 +01:00
odoo_sh.rst [IMP] *: introduce tables of contents in top-level app pages 2021-07-07 14:56:38 +02:00
upgrade.rst [IMP] upgrade: add note on bank synch neutralization 2023-11-22 14:55:20 +00:00