Skip to content

Add support for Content Security Policy via an optional parameter#99

Open
james-otten wants to merge 1 commit intoyoshiharuyamashita:masterfrom
james-otten:james/csp
Open

Add support for Content Security Policy via an optional parameter#99
james-otten wants to merge 1 commit intoyoshiharuyamashita:masterfrom
james-otten:james/csp

Conversation

@james-otten
Copy link
Copy Markdown
Contributor

Content Security Policy (CSP) is often used as a part of a defense in depth based approach to prevent common web vulnerabilities.

With this change, a user can setup their own CSP through an optional site parameter "csp".
If the parameter is set, a meta element is added to the page which contains the user's policy.

More info on CSP is available on MDN: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP

Content Security Policy (CSP) is often used as a part of a defense in depth based approach to prevent common web vulnerabilities.

With this change, a user can setup their own CSP through an optional site parameter "csp".
If the parameter is set, a meta element is added to the page which contains the user's policy.

More info on CSP is available on MDN: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant