origami-cms / cms

Open source, flexible, and easy to use CMS for Node.js
http://www.origami.so
50 stars 2 forks source link

Add CSP security with Helmet.js #4

Open tristanMatthias opened 5 years ago

tristanMatthias commented 5 years ago

I'm submitting a ...

For project (Choose one)

What is the current behavior? There is currently no protection with CSP (Content Security Policy). This should be enabled to provide further protection.

What is the expected behavior? A good default setting, with the option to override from the Origami file

What is the motivation / use case for changing the behavior? Better security

Please tell us about your environment: Any Origami project