3

Include

<meta http-equiv="Content-Security-Policy" content="default-src 'self';">

Everywhere....

Company just lost a big contract because thier dumb software didn't find this tag and classified security as "F"..... It was the ONLY find in thier dumb report.

Comments
Add Comment