Remove default CSP headers from core

Created on 3 June 2024, 10 months ago
Updated 17 June 2024, 10 months ago

Problem/Motivation

In anticipation of 📌 Add a default CSP and clickjacking defence and minimal API for CSP to core Active , if the CSP module is installed but a directive is not enabled, then any default headers set by core should be removed.

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

📌 Task
Status

Fixed

Version

2.0

Component

Code

Created by

🇨🇦Canada gapple

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024