Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Best practice regarding Security-Relevant HTTP Headers
#14
Hi,

CSP is not easy to implement in any circumstance, even if you have a static web site composed only of a bunch of HTML, CSS and JS files. On the contrary, CSP is hard... depending on the level of your requirements it can be *very* hard. Believe me, I've been there.

It is much simpler for you to just migrate to latest IW 15 and use the built-in functionality which is already prepared.

The problem is not only adding CSP headers to your response. All HTML, CSS and JS needs to be also considered and probably changed in order to comply with CSP.
Reply


Messages In This Thread
RE: Best practice regarding Security-Relevant HTTP Headers - by Alexandre Machado - 05-01-2020, 02:38 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)