Problem/Motivation
I'd like to implement the security headers best practices in Rocketship
https://www.keycdn.com/blog/http-security-headers
- CSP
- Permissions-Policy
Proposed resolution
- Update seckit settings
- Add CSP module for better CSP header support
Issue fork dropsolid_rocketship_profile-3340530
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
ducktape commented- Added CSP module
- Added patch for Permissions Policy to seckit
- Updated seckit config for PP & CSP
Comment #4
ducktape commentedCleaned up the config
Comment #5
nginex commentedComment #8
msteurs commentedComment #9
msteurs commentedComment #10
msteurs commented