Hacker News new | ask | show | jobs
by lol768 3943 days ago
You might find the Content-Security-Policy-Report-Only header useful for identifying CSP issues and deploying policies without actually blocking anything.