Comments (6)
I think it's fine to do this in a major version bump. Which browsers still need the old header exactly? On the other hand having it disabled by default, does it slow down things still?
from csp.
Browsers have varying support for CSP. Some use different headers (like X-WebKit-CSP
instead of Content-Security-Policy
) where others have different names for directives (like allow
instead of default-src
). This module currently tries to figure those things out, but I intend to remove them unless people think doing so is a bad idea.
from csp.
Definitely 👍. We've been running with browser sniffing off since #32 landed -- my biggest concern at that time was the cacheability of browser-sniffed requests.
from csp.
TBH I too have browser sniffing off for years.
from csp.
👍 I had to turn off browser sniffing too and reasons for removal make sense.
from csp.
This has been addressed in helmet@4
and [email protected]
.
I'm going to be archiving this repository soon and moving everything to https://github.com/helmetjs/helmet/, so feel free to open an issue there if you run into any problems.
from csp.
Related Issues (20)
- Add support for trusted-types HOT 7
- No CSP headers for iOS WebViews HOT 5
- how to choose? With helmet or helmet-csp? It's all yours, I don't know which one to choose? HOT 2
- Cannot Use Function Instead of Array as Value of Directive HOT 8
- safari will ignore whole rule HOT 4
- Convert module to TypeScript HOT 1
- reportTo directive HOT 4
- Upgrade dependency for platorm to version > 1.3.5 HOT 4
- How to add a specific sha256 to scriptSrc? HOT 4
- 'unsafe-inline' should be allowed in style-src and connect-src HOT 1
- Issue due to extra x-content-security-policy, x-webkit-csp headers HOT 4
- Add support for script-src-elem directive HOT 3
- Unable to use with Webpack when targeting Node HOT 18
- TypeScript typings are broken HOT 3
- Header require-sri-for deprecated HOT 7
- Header report-uri deprecated HOT 4
- res.setHeader is not a function HOT 5
- Bowser.getParser is not a function HOT 9
- object-src directive checker error HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from csp.