Add Content-Security-Policy

#72 · closed · 2 comments

View on GitHub ↗

mhils

As a second barrier against XSS, we should addding a CSP directive (self, unsafe-eval) when moving to Flask. We need to consider that you can fetch request content from the same URL, so we must either separate that (other port) or add another form of authentication (might ref #42)

Comments

mhils

blocked by #71

mhils

implemented.