Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Issue #1329. Add a Content-Security-Policy-Report-Only header.
This allows xhr, fonts, images, scripts, css from webcompat.com (or localhost). It also allows script from google-analytics.com. Let's leave it on for a week or so and see what we need to tweak before enabling the policy (and where to file bugs to improve security).
- Loading branch information