Menu

#685 Add a CORS Policy

Unknown
open
None
Unknown
Security
Unknown
Unknown
Unknown
Unknown
2024-08-21
2024-08-21
No

See https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy

By default the base URL have to be used with default-src, but the administrator should be able to allow more origins because the templating system provide a way to include external resources (CSS/JS).

Discussion


Log in to post a comment.