mirror of https://github.com/tailscale/tailscale/
cmd/derper: set Content-Security-Policy on DERPs.
It's a basic "deny everything" policy, since DERP's HTTP server is very uninteresting from a browser POV. But it stops every security scanner under the sun from reporting "dangerously configured" HTTP servers. Updates tailscale/corp#3119 Signed-off-by: David Anderson <danderson@tailscale.com>pull/3421/head
parent
33c541ae30
commit
db800ddeac
Loading…
Reference in New Issue