Closed qroac closed 2 years ago
sorry to respond so late...
the headers option does not handle the csp headers. the csp headers you are seeing is from default loader.json. you can either
1) use the loader with a custom json file or 2) just use the setter callback
that behavior intended since this plugin was created to use a json or lib to avoid writing the csp by hand.
Kirby v3, security headers plugin and dependencies installed via composer in the most recent versions by the time of writing.
I set up this plugin to output CSP headers matching required hostnames from the website like this:
But it seems to be ignored, as the headers sent to the browser are these: