open-contracting / software-development-handbook

A guide for developers of OCP's tools
https://ocp-software-handbook.readthedocs.io/en/latest/
Other
4 stars 1 forks source link

Document implementation of Content-Security-Policy #110

Open jpmckinney opened 2 months ago

jpmckinney commented 2 months ago

Add to JS page and link from HTML/CSS

Also add subresource integrity instructions (tool linked from MDN, use default SHA384)

And same for X-Content-Type-Options