Hi
I have been looking for the right setting of CSP (Content-Security-Policy). I couldn't find it so I first tried with
Content-Security-Policy "default-src 'self';
but then my pages were not rendered correctly aymore.
It seems to be workling now with the following setting:
Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:";
Can anyone confirm this is the expected settings? Can I remove the unsafe-eval from the script?
Thanks