gbowne1 / spmssite

The code for my old business website.
GNU General Public License v3.0
8 stars 31 forks source link

Add Content Security Policy #47

Open gbowne1 opened 2 years ago

gbowne1 commented 2 years ago

Prerequisites

Current Behavior

There currently is no Content Security Policy (CSP) for this site.

https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP

Expected Behavior

Google Lighthouse in Google Chrome reports no Content Security Policy (CSP).

Steps to Reproduce

[TODO]

gbowne1 commented 2 years ago

This is coming from Google Maps:

Here is some reference docs:

https://developers.google.com/maps/documentation/javascript/content-security-policy https://stackoverflow.com/questions/13228825/google-maps-api-script-does-load-due-to-content-security-policy https://content-security-policy.com/examples/google-maps/