Skip to content

Add a Content-Security-Policy with a nonce#137

Open
ktreimann wants to merge 1 commit intojustinbleach:masterfrom
ktreimann:csp-nonce
Open

Add a Content-Security-Policy with a nonce#137
ktreimann wants to merge 1 commit intojustinbleach:masterfrom
ktreimann:csp-nonce

Conversation

@ktreimann
Copy link
Copy Markdown

Security scanners and pentesters complain about the lack of a Content-Security-Policy header on the small script generated by redirectToIdentityProvider. This addresses that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant