Skip to content

[TASK] Implement Content-Security-Policy (CSP): report-only → enforce #39

Description

@smcnab1

Task Description

Add CSP with sensible defaults and nonces/hashes; collect violations, iterate, then enforce without breakage.

Acceptance Criteria

  • CSP present in report-only with low/no violations
  • CSP enforced without functional regressions
  • Policy documented and versioned

Related Issues / PRs

No response

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions