Closed dorianmariecom closed 2 years ago
@dorianmariefr: require-trusted-types-for
is implemented in v6.4.0
. Does this meet your needs?
@lgarron I don't maintain an application that uses secure_headers anymore
Alright, thanks! I'll mark this as closed, and we can use new issues if there is something to change about the implementation.
From https://csp-evaluator.withgoogle.com :
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/require-trusted-types-for
Example:
Feature Requests
Adding a new CSP directive
https://w3c.github.io/webappsec-trusted-types/dist/spec/#require-trusted-types-for-csp-directive
Seems like there is only
'script'
as a valid value, not sure