Slide 52
Slide 52 text
Content-Security-Policy:
default-src 'self';
img-src 'self' data:;
script-src: 'self' https://api.example.com
!
Content-Security-Policy-Report-Only:
default-src 'self';
img-src 'self' data:;
script-src: 'self' https://api.example.com