-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Igal,

On 8/11/20 23:23, Igal Sapir wrote:
> Chris,
>
> On Mon, Aug 10, 2020 at 12:20 PM Martin Grigorov
> <mgrigo...@apache.org <mailto:mgrigo...@apache.org>> wrote:
>
>
> On Tue, Jul 28, 2020, 16:48 Christopher Schultz
> <ch...@christopherschultz.net
> <mailto:ch...@christopherschultz.net>> wrote:
>
> All,
>
> I was looking at this PR[1] and wondering why we have huge swaths
> of CSS and HTML in a Java source file, instead of using e.g. JSP
> or some other content-generation framework.
>
> I know, I hate JSP, too, but having large blocks of HTML and CSS
> in Java strings is just ... awful.
>
> Also, is there a particular reason we are using embedded CSS in
> the pages instead of an external CSS file?
>
> Ultimately, it would be a good idea to move all CSS and even
> styles into a separate CSS file so we can tighten-up the Content
> Security Policy on the manager app. This can help prevent attacks
> if there happens to be some kind of XSS vulnerability hiding in
> there somewhere.
>
> Any objections to evicting the CSS to begin with?
>
>
>> It's funny, I was thinking the same thing a couple of weeks ago
>> but didn't want to cause a merge conflict for the PR so waited to
>> see what's going on with that, though as I commented on it I
>> don't like that it changes the theme colors, etc.
>
>> If you are already working on that then great.  If you haven't
>> started, and you have better things to do, I'd be happy to clean
>> that up so please LMK.

I've got a bunch of ACAH presentations to get done, so I'd be
perfectly happy to have you do this work :)

- -chris
-----BEGIN PGP SIGNATURE-----
Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl8z7ogACgkQHPApP6U8
pFjMeBAAh3teSq45voa1dMj2BGTPmhTLq2Eu6y4L5KqjABZergqapfNZsKRUuiTZ
ze1Jpmjb+YfRkspi0nHZMN8K8LBibSh5cr+6SRydZSqada2vNdM1j4y2bCGwrJuY
fykU8adsIzbkQreN+70mzyObJFruUz4o/+PE7c5dc6xQXnZQ7TmxZxfHmAeVegNz
DS0itJXdc8Spnl9HFG+bZwQcKAMflakCxyb/aCjfkhZ4yxUwmX8ReL7ihQWoVH7b
IO85ipw8mJ6h89IfQMN89ZKzs2KRFTbVk7jepxOi4YRoG8P1a2lNcigKBQ6qi0DF
aGaiiTck58+q5uvWQDE7kWSm1MGmLz6bec5zknQ7Smgw2sQqykFLRDDia/v/gKRn
B1nmGp0aB8P5sReP3F/ipOFTXXOVT4N/8MHNv3EK2M+b5isYDzyCF96f7Q8ha+mA
NPh+CJlCWTpEvRjSuwd12DVL/12WyDtCI8fOHlrCCI2ks5L45JWFtQX26WvYZl6n
Z2WO4yg58CjTTxr66VAnuriZra6gSRfZyJCTUp2wImcrAR9pBiM7uB6D1e03hgP3
qiMSY/jSLRvv+aaXQTpc+ePFInKWE+iEgNh7s2njgYrS0dcn5ahhFgeioXtDV8ex
nTbucrv9ArTZ+XywnQSI8UHDA3bb2gAM+xnb31d8p83TEDv5how=
=jGCx
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to