From PR #66 review (GLM 5.1, finding #15):
Dashboard serves HTML without a CSP header. Add at minimum:
Content-Security-Policy: default-src 'self'; script-src 'self'
This provides defense-in-depth against XSS beyond the escapeHtml()
sanitization already in place.
From PR #66 review (GLM 5.1, finding #15):
Dashboard serves HTML without a CSP header. Add at minimum:
This provides defense-in-depth against XSS beyond the escapeHtml()
sanitization already in place.