Content Security Policy & Best Practices
This article is mostly on configuration with nginx and maybe a little on IIS.
Notes:
Notes:
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors
- https://csp-evaluator.withgoogle.com
- https://securityheaders.io/