Skip to content

Content Security Policy rules to consider #37

@philwareham

Description

@philwareham

When we come to tighten up the CSP, here are all the potential rules it can have (see below). Note that some of these won't be applicable to our sites but we can either lock them down if unused or omit the rule. Some of these (not all) fallback to the default-src rule anyway if not defined - and I think we have set that to 'none' for each site - so that provides a modicum of security.

We can tick of each as they are considered/implemented/discarded:

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions