Skip to content

Instantly share code, notes, and snippets.

@felixrieseberg
Created July 14, 2021 20:38
Show Gist options
  • Save felixrieseberg/cf59210204af678db5434bab3d07ce96 to your computer and use it in GitHub Desktop.
Save felixrieseberg/cf59210204af678db5434bab3d07ce96 to your computer and use it in GitHub Desktop.
Stripe, iframe, and CSP
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<!-- https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP -->
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src https://js.stripe.com 'self'; connect-src https://api.stripe.com; frame-src https://js.stripe.com https://hooks.stripe.com">
<meta http-equiv="X-Content-Security-Policy" content="default-src 'self'; script-src https://js.stripe.com 'self'; connect-src https://api.stripe.com; frame-src https://js.stripe.com https://hooks.stripe.com">
<title>Hello World!</title>
<script src="https://js.stripe.com/v3" async></script>
</head>
<body>
<h1>Hello World!</h1>
</body>
</html>
// Modules to control application life and create native browser window
const {app, BrowserWindow} = require('electron')
const path = require('path')
function createWindow () {
// Create the browser window.
const mainWindow = new BrowserWindow({
width: 800,
height: 600
})
// and load the index.html of the app.
mainWindow.loadFile('index.html')
// Open the DevTools.
mainWindow.webContents.openDevTools()
}
// This method will be called when Electron has finished
// initialization and is ready to create browser windows.
// Some APIs can only be used after this event occurs.
app.whenReady().then(() => {
createWindow()
app.on('activate', function () {
// On macOS it's common to re-create a window in the app when the
// dock icon is clicked and there are no other windows open.
if (BrowserWindow.getAllWindows().length === 0) createWindow()
})
})
// Quit when all windows are closed, except on macOS. There, it's common
// for applications and their menu bar to stay active until the user quits
// explicitly with Cmd + Q.
app.on('window-all-closed', function () {
if (process.platform !== 'darwin') app.quit()
})
// In this file you can include the rest of your app's specific main process
// code. You can also put them in separate files and require them here.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment