Skip to content

Conversation

@Sigmonia
Copy link
Contributor

-- Note: comments are removed during application execution, so they do not appear in the Response Header

Rationale

Add comments to the CSP

Changes

  • add explanatory comments to the CSP declarations

-- Note: comments are removed during application deployment
@Sigmonia Sigmonia self-assigned this Feb 17, 2025
Copy link
Member

@labkey-tchad labkey-tchad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not quite sure the point of these comments. One can look at any CSP documentation to find out what the directives mean.
It would be more useful to have comments explaining why the various directives have these settings. (e.g. why is object-src totally locked out)

@Sigmonia Sigmonia merged commit 3909ce7 into develop Feb 19, 2025
5 checks passed
@Sigmonia Sigmonia deleted the fb_cspComments branch February 19, 2025 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants