Content Security Policy produces a javascript error.
Gitea
3
Posts
3
Posters
21
Views
3
Watching
-
many apps require browser features like javascript eval() for example which would be blocked with the strict rules. This does not automatically mean the app is insecure or so, blindly applying those rules without understanding the apps does not add much benefit there. There are various ways apps can protect unsafe operations besides csp rules.
If you are curious about gitea usage here, you can try to tweak them to narrow down the issue or ask upstream.