Move away from X-CSP and use the Content-Security-Policy header instead

Bug #1277294 reported by François Marier
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Libravatar (obsolete)
Fix Released
Medium
François Marier

Bug Description

Firefox is deprecating the X-Content-Security-Policy: https://groups.google.com/d/topic/mozilla.dev.security/lW4vb0WWCJE/discussion

We should move to the CSP 1.0 header (Content-Security-Policy) as soon as possible.

This also means that it will start working in Chromium-based browsers.

Changed in libravatar:
status: Confirmed → Fix Committed
Changed in libravatar:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.