Closed erikhubers closed 4 years ago
Hey there,
I noticed no CSP headers defined in Afterlogic WebMail Lite/Pro. Maybe it's a nice to provide some for additional security. I've also run the demo page through securityheaders.com, the score (D) isn't really top notch.
Thank you, I've notified the developers on this.
The feature is implemented in Afterlogic WebMail 8.5.1: https://afterlogic.com/docs/webmail-pro-8/security/content-security-policy
Hey there,
I noticed no CSP headers defined in Afterlogic WebMail Lite/Pro. Maybe it's a nice to provide some for additional security. I've also run the demo page through securityheaders.com, the score (D) isn't really top notch.