Skip to content

The CSP anaylsis component ignores a "default none" setting when recommending settings #269

@argl

Description

@argl

Feedback received:

The CSP anaylsis component ignores a "default none" setting when recommending settings. For instance, it suggests setting "frame-anchestors" at the XFO header. That is - to my understanding - useless, when CSPs default is set to none.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs decisionA decision is required before this issue can proceed.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions