google / csp-evaluator

https://csp-evaluator.withgoogle.com
Apache License 2.0
315 stars 45 forks source link

script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' reported as "all good" #24

Open midist0xf opened 3 years ago

midist0xf commented 3 years ago

I would like to highlight the fact that the above policy is reported as safe. Is this intended? From what I understood 'unsafe-inline' could remove the defense. I would expect this reported as an High severity finding. Am I missing something? Thanks image