lighthouse-security icon indicating copy to clipboard operation
lighthouse-security copied to clipboard

CSP Meta Audit should test if value is valid

Open jbmoelker opened this issue 7 years ago • 1 comments

Also are multiple <meta name="Content-Security-Policy" value="..."> tags supported?

jbmoelker avatar Aug 21 '17 20:08 jbmoelker

Should CSP meta be considered a good practice or avoided?

CSPs preferred delivery mechanism is an HTTP header. -- Google Web Fundamentals

If should be avoided, that's the advice we should give. Also we could link the helpText directly to the meta tag section.

jbmoelker avatar Aug 21 '17 20:08 jbmoelker