Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable content security policy in report-only mode #6642

Merged
merged 1 commit into from Feb 20, 2020

Commits on Feb 10, 2020

  1. Enable content security policy in report-only mode

    - If CSP were not in report-only mode, this would prevent
      * framing the site (already prevented with x-frame-options)
      * embedding any applets, objects, or embeds
      * block any mixed content
    - Instead violations of these policies will be reported.
      They can be reported to Sentry if CSP_REPORT_URI is configured
    davidfischer committed Feb 10, 2020
    Copy the full SHA
    8271501 View commit details
    Browse the repository at this point in the history