Skip to content

Remove Rack::Protection::ContentSecurityPolicy defaults #1484

Closed
@baelter

Description

Rack::Protection::ContentSecurityPolicy has script-src and style-src defaults making it impossible leave them out of the header to have them fallback to default-src.

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions