Does a *.example.com for a content security policy header also match example.com?

前端 未结 2 504
难免孤独
难免孤独 2021-01-08 00:51

Say I have this header set on mywebsite.com:

Content-Security-Policy: script-src self https://*.example.com

I know it will all

2条回答
  •  太阳男子
    2021-01-08 01:04

    According to Mozilla's docs you should include 'self' as well as *.example.com in the CSP header if you want to include the base domain.

提交回复
热议问题