Skip to content

Content-Security-Policy in report-only mode #2

@pphunor72

Description

@pphunor72

If I set a configuration object to csp, and that configuration object contains reportOnly: true, then beside of Content-Security-Policy-Report-Only header Content-Security-Policy is also added with default settings. This was the intent? Because it prevents monitoring and testing custom policies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions