Strict CSP (Content-Security-Policy) for Next.js hybrid apps https://web.dev/strict-csp/
-
Updated
May 29, 2023 - TypeScript
Strict CSP (Content-Security-Policy) for Next.js hybrid apps https://web.dev/strict-csp/
Securing create-react-app hosted on nginx
Lint a Content-Security-Policy for XSS holes locally — 'unsafe-inline', wildcards, missing directives, and allowlisted hosts that bypass CSP (JSONP/AngularJS). Nonce/strict-dynamic aware. Deterministic CLI, JSON/MD reports, no website.
Add a description, image, and links to the strict-dynamic topic page so that developers can more easily learn about it.
To associate your repository with the strict-dynamic topic, visit your repo's landing page and select "manage topics."