Skip to content

Default Content Security Policy #48

@aantron

Description

@aantron

Emit default CSP headers with:


  • In particular, include a policy for frames, to mitigate clickjacking by default.
  • Add a handler for logging CSP violation reports.
  • Document everything. Link to MDN and offer basic warnings and guidance. Create a CSP tutorial or example.


It's probably best to:

  • Provide an example that shows CSP in action, as well as reporting.
  • Link to the example from Dream.html.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions