Open php-coder opened 9 years ago
Explicitly specify directives that aren't covered by default-src
(like form-action
, see https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5).
Could be useful, here are the Jenkins CSP rules: https://wiki.jenkins.io/display/JENKINS/Configuring+Content+Security+Policy
See for details: