Zelfs de Mozilla site laat steken vallen: https://csp-evaluator.withgoogle.com/
default-src 'none';
connect-src https://api.ssllabs.com https://hstspreload.org https://http-observatory.security.mozilla.org https://securityheaders.io https://tls.imirhil.fr https://tls-observatory.services.mozilla.com https://www.htbridge.com;
font-src 'self' https://fonts.gstatic.com;
frame-ancestors 'none';
img-src 'self';
script-src 'self';
style-src 'self' https://fonts.googleapis.com
Voor wat:
help_outlinescript-src
expand_more
help_outline'self'
'self' can be problematic if you host JSONP, Angular or user uploaded files.
Dan is er nog een probleem met cache-control. Help Icon
Click the icons in the tables below for a more detailed explanation.
HTTP security headers
Name
Value
Setting secure
content-security-policy
default-src 'none'; connect-src https://api.ssllabs.com https://hstspreload.org https://http-observatory.security.mozilla.org https://securityheaders.io https://tls.imirhil.fr https://tls-observatory.services.mozilla.com https://www.htbridge.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'none'; img-src 'self'; script-src 'self'; style-src 'self' https://fonts.googleapis.com, upgrade-insecure-requests; block-all-mixed-content
Page meta security headers not set as secure.