Skip to content
This repository was archived by the owner on Jan 9, 2019. It is now read-only.

[Hint] Content-Security-Policy HTTP header #24

Closed
1 of 2 tasks
molant opened this issue Sep 6, 2018 · 0 comments
Closed
1 of 2 tasks

[Hint] Content-Security-Policy HTTP header #24

molant opened this issue Sep 6, 2018 · 0 comments

Comments

@molant
Copy link
Member

molant commented Sep 6, 2018

Originally reported by @alrra in webhintio/hint#25


  • Check if the header is sent for non-HTML resources (e.g.: on images, fonts, etc.) - done in webhintio/hint@c55bdfb.
  • Check for older deprecated version of the header are sent (i.e.:X-WebKit-CSP, X-Content-Security-Policy).

  • TODO: Look into what other checks we can add for that this (e.g.: validate the content of the header, upgrade-insecure-requests)

See also:

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant