-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Igal,
On 8/11/20 23:23, Igal Sapir wrote: > Chris, > > On Mon, Aug 10, 2020 at 12:20 PM Martin Grigorov > <mgrigo...@apache.org <mailto:mgrigo...@apache.org>> wrote: > > > On Tue, Jul 28, 2020, 16:48 Christopher Schultz > <ch...@christopherschultz.net > <mailto:ch...@christopherschultz.net>> wrote: > > All, > > I was looking at this PR[1] and wondering why we have huge swaths > of CSS and HTML in a Java source file, instead of using e.g. JSP > or some other content-generation framework. > > I know, I hate JSP, too, but having large blocks of HTML and CSS > in Java strings is just ... awful. > > Also, is there a particular reason we are using embedded CSS in > the pages instead of an external CSS file? > > Ultimately, it would be a good idea to move all CSS and even > styles into a separate CSS file so we can tighten-up the Content > Security Policy on the manager app. This can help prevent attacks > if there happens to be some kind of XSS vulnerability hiding in > there somewhere. > > Any objections to evicting the CSS to begin with? > > >> It's funny, I was thinking the same thing a couple of weeks ago >> but didn't want to cause a merge conflict for the PR so waited to >> see what's going on with that, though as I commented on it I >> don't like that it changes the theme colors, etc. > >> If you are already working on that then great. If you haven't >> started, and you have better things to do, I'd be happy to clean >> that up so please LMK. I've got a bunch of ACAH presentations to get done, so I'd be perfectly happy to have you do this work :) - -chris -----BEGIN PGP SIGNATURE----- Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/ iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl8z7ogACgkQHPApP6U8 pFjMeBAAh3teSq45voa1dMj2BGTPmhTLq2Eu6y4L5KqjABZergqapfNZsKRUuiTZ ze1Jpmjb+YfRkspi0nHZMN8K8LBibSh5cr+6SRydZSqada2vNdM1j4y2bCGwrJuY fykU8adsIzbkQreN+70mzyObJFruUz4o/+PE7c5dc6xQXnZQ7TmxZxfHmAeVegNz DS0itJXdc8Spnl9HFG+bZwQcKAMflakCxyb/aCjfkhZ4yxUwmX8ReL7ihQWoVH7b IO85ipw8mJ6h89IfQMN89ZKzs2KRFTbVk7jepxOi4YRoG8P1a2lNcigKBQ6qi0DF aGaiiTck58+q5uvWQDE7kWSm1MGmLz6bec5zknQ7Smgw2sQqykFLRDDia/v/gKRn B1nmGp0aB8P5sReP3F/ipOFTXXOVT4N/8MHNv3EK2M+b5isYDzyCF96f7Q8ha+mA NPh+CJlCWTpEvRjSuwd12DVL/12WyDtCI8fOHlrCCI2ks5L45JWFtQX26WvYZl6n Z2WO4yg58CjTTxr66VAnuriZra6gSRfZyJCTUp2wImcrAR9pBiM7uB6D1e03hgP3 qiMSY/jSLRvv+aaXQTpc+ePFInKWE+iEgNh7s2njgYrS0dcn5ahhFgeioXtDV8ex nTbucrv9ArTZ+XywnQSI8UHDA3bb2gAM+xnb31d8p83TEDv5how= =jGCx -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org