In prod, when loading the console, we were failing to get some
scripts/styles with the error "Executing
inline event handler violates the following Content Security Policy directive 'script-src
'self''. Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-
...') is required to enable inline execution. Note that hashes do not apply to event
handlers, style attributes and javascript: navigations unless the 'unsafe-hashes' keyword
is present. The action has been blocked."
We fix this by disabling inline-critical optimization for prod in the
angular file.
In addition, the web.xml header values are comma-separated -- we forgot
one comma before.
This isn't the prettiest thing, but it replicates the type of view /
edit functionality that we had in the original console.
Of note: this doesn't include input field validation, which would
probably be a good idea to add at some point.