Set a Content-Security-Policy header
Open
Technical Debt
- Dominant language
- Clojure
- Stars
- 66
- Forks
- 28
- Avg merge
- 7d 4h
- Merged PRs (30d)
- 2
Description
It's a security best practice. Currently we only have the (deprecated?) security headers like `X-XSS-Protection` set by ring.middleware.default.
See also #2216
Contributor guide
Assessment
This issue has not been assessed yet.