18F / projects

[WIP] A collection of our projects, past and present
Other
9 stars 3 forks source link

Enable Content Security Policy #25

Open toolness opened 8 years ago

toolness commented 8 years ago

It also looks like Django 1.10 alpha 1 removes all inline JS from django-admin, according to the release notes! (In the meantime, though, we will need to not deliver the CSP headers at the /admin/ endpoint, I guess. 😞)