Skip to content

Add CSP script header.#9184

Draft
dracos wants to merge 1 commit intodevelopfrom
csp-script
Draft

Add CSP script header.#9184
dracos wants to merge 1 commit intodevelopfrom
csp-script

Conversation

@dracos
Copy link
Copy Markdown
Member

@dracos dracos commented Mar 26, 2026

[Initial try to see what happens]

Noting github/secure_headers#511 if a gem was to include its own script tags.

@gbp
Copy link
Copy Markdown
Member

gbp commented Mar 26, 2026

I think we should keep this "OPT_OUT" and use Rails' built-in CSP - see #9187

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants