You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rack::Protection::ContentSecurityPolicy has script-src and style-src defaults making it impossible leave them out of the header to have them fallback to default-src.
The text was updated successfully, but these errors were encountered:
After reading some docs, I agree that a better default would be to set default-src: "'self'" and to remove defaults for script-src, style-src, img-src, connect-src.
Rack::Protection::ContentSecurityPolicy
hasscript-src
andstyle-src
defaults making it impossible leave them out of the header to have them fallback todefault-src
.The text was updated successfully, but these errors were encountered: