Stop using 'self' in the CSP's frame-src directive
'self' allows CSP bypasses by using files hosted on GitLab itself. It is replaced with relative paths to the URLs we know we're using in frames Changelog: security
Showing
Please register or sign in to comment