No Content Security Policy
What we saw
The homepage response carried no content-security-policy header and no equivalent meta tag.
content-security-policy: not sentWhat it means
Your app does not tell browsers which scripts are allowed to run on it. A Content Security Policy is a list of trusted sources.
What could happen
If someone manages to inject code into a page, through a comment field, a URL or a compromised dependency, the browser will run it without question.
- Who can do it
- Someone who found another flaw first
- Reaches
- Every user
- At stake
- User accounts and customer data
How we fix it
We add a Content Security Policy tuned to what your app actually loads, starting in report-only mode so nothing breaks while we verify it.
Fix it yourselfWe fix it