Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
CSP: add additional restrictions (#854)
object-src none and base-uri none are recommended by https://web.dev/articles/strict-csp frame-ancestors none can be added since lib-jobs has no reason to be embedded in an iframe. This is an additional protection, on top of our X-Frame-Options: SameOrigin
- Loading branch information