diff --git a/.reports/embedded-react-sdk.api.md b/.reports/embedded-react-sdk.api.md index b2ced18c5..abf10421f 100644 --- a/.reports/embedded-react-sdk.api.md +++ b/.reports/embedded-react-sdk.api.md @@ -2413,6 +2413,7 @@ export interface GustoProviderProps { // Warning: (ae-forgotten-export) The symbol "LoadingIndicatorContextProps" needs to be exported by the entry point index.d.ts LoaderComponent?: LoadingIndicatorContextProps['LoadingIndicator']; locale?: string; + nonce?: string; portalContainer?: HTMLElement; queryClient?: QueryClient; theme?: Partial; @@ -5159,6 +5160,9 @@ export interface UseJobFormReady extends BaseFormHookReady string | undefined; + // Warning: (ae-internal-missing-underscore) The name "useObservability" should be prefixed with an underscore because the declaration is marked as @internal // // @internal diff --git a/docs/getting-started/proxy-security-partner-guidance.md b/docs/getting-started/proxy-security-partner-guidance.md index 7c0df99a8..fd808cb90 100644 --- a/docs/getting-started/proxy-security-partner-guidance.md +++ b/docs/getting-started/proxy-security-partner-guidance.md @@ -68,6 +68,64 @@ Look up the flows or blocks your app uses, substitute `:param` placeholders with See the [endpoint reference tables](../appendix/endpoint-reference.md) for a human-readable list. Copy the method + path pairs for the components you use and substitute `:param` placeholders with session values at runtime. +## Content Security Policy + +The SDK ships a static stylesheet at `@gusto/embedded-react-sdk/style.css` and injects two runtime `