Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support CSP in html (<meta http-equiv='Content-Security-Policy' content='...'>) #44

Open
rhanka opened this issue Nov 27, 2021 · 1 comment
Labels
bug Something isn't working

Comments

@rhanka
Copy link

rhanka commented Nov 27, 2021

CSP may be implemented with http header in

This is the only way to do it with github pages.

Should be supported, to avoid false-positive of -25 in HTTP scores

@rhanka rhanka changed the title Support CSP in meta http-equiv='Content-Security-Policy' Support CSP in html (<meta http-equiv='Content-Security-Policy' content='...'>) Nov 27, 2021
@revolunet
Copy link
Member

Hi, thanks for reporting, i guess this comes from "Mozilla HTTP Observatory" report ?

Can you confirm the problem also happen here ? https://observatory.mozilla.org/

CSP may be implemented with http header in

in ? html page metas ?

@revolunet revolunet added the bug Something isn't working label Apr 6, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants