|
|
|
|
|
by gkbrk
14 days ago
|
|
The same server that's responsible for sanitizing garbage JS out of user content is also responsible for sending the Content-Security headers. Why would you trust it with one, but not the other? If it's buggy garbage it will also send the wrong headers. |
|
A CSP is more valuable in a larger organization, where the codebase is always at risk of being modified by the organization's worst engineer.