govau / chameleon

🦎 Interactive colour template previews for the Design System
https://designsystem.gov.au/templates/home/customise
MIT License
11 stars 4 forks source link

Investigate content security policy headers #109

Open azerella opened 5 years ago

azerella commented 5 years ago

I think removing helmet is a solid solution as our cloud providers already provide these common XSS headers. It's causing local development grief and adds extra complication that is already being handled by the cloud provider.

We should revisit CSP headers at a later time though.

alex-page commented 5 years ago

It would be good to identify: