internetstandards /

Internet standards compliance test suite
172 stars 35 forks source link

Add compliant CSP for #952

Open baknu opened 1 year ago

baknu commented 1 year ago

mxsasha commented 1 year ago

Since this domain only does a redirect to the GitHub repo, will a CSP of form-action 'none'; base-uri 'none'; default-src 'self'; frame-ancestors 'none' work? That's the minimum our test will accept. Seems like it should be fine, but we don't have a testing setup for this, and would prefer not to break it.

bwbroersma commented 1 year ago

I tested this in browsers, only the end page (that is not redirected) is parsed for CSP. Also see #999, so just add 'basic' 100% CSP.