safe-global / safe-homepage

Safe homepage
https://safe.global
MIT License
5 stars 14 forks source link

feat: add CSP header to all the pages #445

Closed DiogoSoaress closed 2 months ago

DiogoSoaress commented 2 months ago

What it solves

Adds an explicit Content Security Policy to the website pages

How this PR fixes it

Sets the Content Security Policy through a <meta> tag

I tried to keep the allowed src lists as restrictive as possible without braking anything or lose of functionality

github-actions[bot] commented 2 months ago

Branch preview

✅ Deployed successfully in branch deployment:

https://csp--homepage.review.5afe.dev

DiogoSoaress commented 2 months ago

But if the ID is always fixed

Yes, in this case the Contentful space ID remains the same