helmet
helmet copied to clipboard
helmet default directives doesnt match helmet-csp default directives
while going from helmet to helmet csp i noticed that form-action 'self' is not part of helmet-csp default directives.
is there a reason for this? is it safe to omit form-acion?
i see you maintain both libraries so im just wondering about the difference
Good point. helmet-csp is out of date. I'll update it.
For anyone running into this as well you can add a form-action: 'self' manually as a temporay fix if you're using helmet-csp
Published [email protected]
to fix this. Thanks for reporting!