securityheaders / securityheaders-bugs

Bug tracker for https://securityheaders.io
20 stars 0 forks source link

Does not read Content Security Policy from html meta tag #93

Closed Zaita closed 3 years ago

Zaita commented 3 years ago

When scanning and using HTML meta tag for the CSP, this does not get detected.

image

fzipi360 commented 3 years ago

This is still a problem. Any thoughts here? Can this be checked?

ScottHelme commented 3 years ago

Hi,

We only scan HTTP response headers and not meta tags in the page, this is why the policy will not be picked up!

Cheers,

Scott.