dddeastanglia / DDDEastAnglia

DDD East Anglia website
https://www.dddeastanglia.com
7 stars 10 forks source link

Add Feature Policy header #370

Open philpursglove opened 5 years ago

philpursglove commented 5 years ago

Add a http header for Feature Policy - see https://scotthelme.co.uk/a-new-security-header-feature-policy/

Extend the existing SecurityHeadersFilter to add Feature-Policy.

philpursglove commented 5 years ago

Looking at Scott Helme's blog and the feature names he uses in his examples vs. the feature names listed here, I think this needs to wait a bit until Feature Policy is a bit more done that it currently is. (That said, I think for almost every feature our policy just needs to run it off...)