DEV Community

Discussion on: Frontend Security: Content Security Policy

Collapse
 
jankapunkt profile image
Jan Küster

Why am I not surprised that some clients literally come up with such decisions :-/
But under these circumstances I totally agree - better having them edit (a part of) the CSP than having none. I wonder if this would be implemented in a workflow, where the system (using include/exclude lists) or a human can review these edits, before actually publishing them.

Thread Thread
 
madsstoumann profile image
Mads Stoumann

Yes, any changes to the "CSP-config-block" can be previewed and verified before published.