stoolball-england / stoolball-org-uk

A rebuild of the Stoolball England website in Umbraco
Other
3 stars 0 forks source link

Content-Security-Policy should be updatable per-page #210

Closed sussexrick closed 4 years ago

sussexrick commented 4 years ago

So that it can only be relaxed for the likes of Google Maps or Facebook on specific pages that need that.

See whether https://docs.nwebsec.com/en/aspnet4/ is an option

sussexrick commented 4 years ago

Use a custom action filter attribute, inheriting ActionFilterAttribute and IActionFilter. Also need for #269.