damienbod / AspNetCoreHybridFlowWithApi

Different ASP.NET Core applications using OpenID Connect Hybrid flow Code Flow, Code Flow with PKCE, JWT APIs, MFA examples
https://damienbod.com/2018/02/02/securing-an-asp-net-core-mvc-application-which-uses-a-secure-api/
MIT License
364 stars 71 forks source link

make passing reference to CSP.UseCspReportOnly, Explain CSP2 CSP3 #1

Open damienbod opened 6 years ago

damienbod commented 6 years ago

reported by snomad

Maybe make passing reference to CSP.UseCspReportOnly, super helpful on initial efforts into CSP. I am still lost on CSP level 2 and level 3 and just how much of a priority they should be. CanIUse shows CSP 1 at 94% globally, CSP2 at 80%. Not sure what to aim for.

Scott Helme You can use CSP 2 and CSP 3 features and be backwards compatible. At a minimum I'd say CSP 2.