Skip to content

Improvement: Add Content Security Policy headers #102

@LaGodxy

Description

@LaGodxy

Summary

The app lacks a Content Security Policy header, making it vulnerable to XSS attacks.

Acceptance Criteria

  • CSP header configured in next.config.ts
  • Nonce-based inline script allowlist
  • Report-only mode first, then enforce
  • CSP violation reporting endpoint

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions