securityheaders / securityheaders-bugs

Bug tracker for https://securityheaders.io
20 stars 0 forks source link

Content Security Policy: getting an A+ grade without XSS protection #68

Open sebkln opened 5 years ago

sebkln commented 5 years ago

If Content-Security-Policy: frame-ancestors 'self' is added to a website (and the other relevant Security Headers are also in place), the result is an A+ grade.

Can I assume that this is not the intended behaviour? With the missing script-src and default-src directives there's no XSS protection.