github / secure_headers

Manages application of security headers with many safe defaults
MIT License
3.16k stars 252 forks source link

CSP Report-uri deprecated, replaced by report-to #512

Open martindaehn23 opened 1 year ago

martindaehn23 commented 1 year ago

Adding a new CSP directive

Report-uri seems to be depricated: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-uri Instead we want to use both, report-uri and report-to, to be future proof and backward compatible.