Skip to content

recommend setting form-action to 'none', 'self' and specific domains for Content-Security-Policy #524

@thestinger

Description

@thestinger

This won't fall back to default-src since it was introduced in v2.

Eventually, when CSP v3 is stable, navigate-to will be similar, but navigate-to is a much broader feature that's harder to use. Sites generally have very few origins where they need to submit forms, but probably do have a lot of external links, etc. they don't want to allow list.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions