GaProgMan / OwaspHeaders.Core

Inject OWASP recommended HTTP Headers for increased security in a single line
https://www.nuget.org/packages/OwaspHeaders.Core/
MIT License
282 stars 35 forks source link

Cross-Origin-Embedder-Policy not supported #74

Open jamie-taylor-rjj opened 1 year ago

jamie-taylor-rjj commented 1 year ago

10k ft View

The HTTP Cross-Origin-Embedder-Policy (COEP) response header configures embedding cross-origin resources into the document.

Source: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Embedder-Policy

OWASP recommended value (as of May 11th, 2023): Cross-Origin-Embedder-Policy: require-corp

This value means that "A document can only load resources from the same origin, or resources explicitly marked as loadable from another origin."

Resources