All checks were successful
check / check (push) Successful in 4s
Set CSP header on all SPA-served responses to provide defense-in-depth against XSS. The policy restricts scripts, styles, and all other resource types to same-origin only, matching the SPA's actual behavior (external CSS/JS files, same-origin fetch API calls, no WebSockets or external resources).
3.4 KiB
3.4 KiB