Skip to content

bugfix for boolean CSP directives

Compare
Choose a tag to compare
@oreoshake oreoshake released this 09 May 20:46
· 471 commits to main since this release

@stefansundin noticed that supplying false to "boolean" CSP directives (e.g. upgrade-insecure-requests and block-all-mixed-content) would still include the value.