4 ms·
I hope 100% of the respondents answer that they've used "Content-Security Policy (CSP)" as it's there by default and by answering anything else, they probably o
by capableweb 3y ago
I hope 100% of the respondents answer that they've used "Content-Security Policy (CSP)" as it's there by default and by answering anything else, they probably out themselves as basically not knowing their own space where they work.
- chrismorgan 3y agoAre you thinking of something else? Perhaps the same-origin policy, the thing that requires CORS if you need to do various cross-origin stuff? Because CSP is not something there by default.
- bryanrasmussen 3y agoI mean there are things you do like turn it on the server etc. So if you haven't done anything to work with something can you say you've 'used' it. Perhaps people just demonstrate a different opinion of linguistic usage?
- simonw 3y agoWhat have you used CSP for?
- wryanzimmerman 3y agoWhat do you mean by there by default? There are a lot of ways you could send a valid response without including that header or tag, any policies are not one-size-fits all and could be different. Maybe you’re using a full-stack framework which is managing it for you? Or maybe you’re confusing it with CORS?