content-security-policy.com
content-security-policy.com copied to clipboard
`base-uri` is missing
https://www.w3.org/TR/CSP2/#directive-base-uri
I would also suggest adding base-uri 'none'; to the examples because it does not fallback to default-src.
Good suggestion, we'll get that updated.