Server injects HTML that turns off most security features in a browser #413

Closed
opened 2025-12-21 16:41:01 +01:00 by backuprepo · 2 comments
Owner

Originally created by @sparky8251 on GitHub (Feb 12, 2019).

Describe the bug
This bit of code turns off all kinds of safety settings whenever index.html (the top level of the web UI) is loaded.

Expected behavior
Web app should function properly without disabling every security function known to man.

Originally created by @sparky8251 on GitHub (Feb 12, 2019). **Describe the bug** [This bit of code turns off all kinds of safety settings whenever index.html (the top level of the web UI) is loaded](https://github.com/jellyfin/jellyfin/blob/eb4b7051676b7493a57a99a821d5dd38bd9d4919/MediaBrowser.WebDashboard/Api/PackageCreator.cs#L138). **Expected behavior** Web app should function properly without disabling every security function known to man.
backuprepo 2025-12-21 16:41:01 +01:00
Author
Owner

@stale[bot] commented on GitHub (Jul 29, 2019):

Issues go stale after 60d of inactivity. Mark the issue as fresh by adding a comment or commit. Stale issues close after an additional 7d of inactivity. If this issue is safe to close now please do so. If you have any questions you can reach us on Matrix or Social Media.

@stale[bot] commented on GitHub (Jul 29, 2019): Issues go stale after 60d of inactivity. Mark the issue as fresh by adding a comment or commit. Stale issues close after an additional 7d of inactivity. If this issue is safe to close now please do so. If you have any questions you can reach us on [Matrix or Social Media](https://jellyfin.readthedocs.io/en/latest/getting-help/).
Author
Owner

@dkanada commented on GitHub (May 2, 2020):

resolved in #2966

@dkanada commented on GitHub (May 2, 2020): resolved in #2966
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: starred/jellyfin#413
No description provided.