130da4c7702c81ce819af51601e36400c3afbcea jcasper Fri Apr 12 14:28:31 2019 -0700 Updating jstree library version for hgCollection and hgHubConnect, refs #23296 diff --git src/lib/htmshell.c src/lib/htmshell.c index 46d1f19..346a5e6 100644 --- src/lib/htmshell.c +++ src/lib/htmshell.c @@ -957,30 +957,31 @@ // Trick for backwards compatibility with browsers that understand CSP1 but not nonces (CSP2). dyStringAppend(policy, " 'unsafe-inline'"); // For browsers that DO understand nonces and CSP2, they ignore 'unsafe-inline' in script if nonce is present. char *noncePolicy=getNoncePolicy(); dyStringPrintf(policy, " %s", noncePolicy); freeMem(noncePolicy); dyStringAppend(policy, " code.jquery.com"); // used by hgIntegrator jsHelper and others dyStringAppend(policy, " www.google-analytics.com"); // used by google analytics // cirm cdw lib and web browse dyStringAppend(policy, " www.samsarin.com/project/dagre-d3/latest/dagre-d3.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/d3/3.4.4/d3.min.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/jquery/1.12.1/jquery.min.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/jstree/3.2.1/jstree.min.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/bowser/1.6.1/bowser.min.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/jstree/3.3.4/jstree.min.js"); +dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/jstree/3.3.7/jstree.min.js"); dyStringAppend(policy, " login.persona.org/include.js"); dyStringAppend(policy, " cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js"); // expMatrix dyStringAppend(policy, " ajax.googleapis.com"); dyStringAppend(policy, " maxcdn.bootstrapcdn.com"); dyStringAppend(policy, " d3js.org/d3.v3.min.js"); // jsHelper dyStringAppend(policy, " cdn.datatables.net"); dyStringAppend(policy, ";"); dyStringAppend(policy, " style-src * 'unsafe-inline';"); /* more secure method not used yet