Closed tjbo closed 5 years ago
Previously we we're creating CSP headers, even they didn't exist on the previous request. https://github.com/helpscout/proxypack/compare/v0.1.7...v0.1.8
In this fix, we first check if the headers exist before merging them in. This would means that since the local domain works without the header that CSP is OptIn, and hence we only need to add it when it has already been added.
Previously we we're creating CSP headers, even they didn't exist on the previous request. https://github.com/helpscout/proxypack/compare/v0.1.7...v0.1.8
In this fix, we first check if the headers exist before merging them in. This would means that since the local domain works without the header that CSP is OptIn, and hence we only need to add it when it has already been added.