"Note: It is known that having both Content-Security-Policy and X-Content-Security-Policy or X-Webkit-CSP causes unexpected behaviours on certain versions of browsers. Please avoid using deprecated X-* headers." https://content-security-policy.com/ We send all three. Should we fix this?
There's no reason to use anything but just Content-Security-Policy at this point.
Severity: normal → enhancement
Status: UNCONFIRMED → NEW
Ever confirmed: true
To firstname.lastname@example.org:mozilla-bteam/bmo.git a312a33e3..f25ef8dde master -> master
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
This is now live.
Status: RESOLVED → VERIFIED
(In reply to April King [:April] from comment #1) > There's no reason to use anything but just Content-Security-Policy at this > point. I've filed: https://github.com/mozilla/http-observatory/issues/223
You need to log in before you can comment on or make changes to this bug.