David Jackson
Results
1
comments of
David Jackson
I think the architecture of WET prevents us from implementing a good CSP without using 'unsafe-eval' or 'unsafe-inline' in the script-src. For example, this code from the canada.ca template: `...