Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Best practice regarding Security-Relevant HTTP Headers
#8
From the release notes.

"Content Security Policy (CSP) support. Read more about CSP here. https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
Good part of the rendering engine was refactored to remove inline JavaScript, CSS and unsafe code (according to CSP best practices). A nonce is now included in all scripts/link files."

I will ask Alexandre to respond further.
Reply


Messages In This Thread
RE: Best practice regarding Security-Relevant HTTP Headers - by kudzu - 11-05-2019, 02:38 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)