David Jackson

Results 1 comments of David Jackson

I think the architecture of WET prevents us from implementing a good CSP without using 'unsafe-eval' or 'unsafe-inline' in the script-src. For example, this code from the canada.ca template: `...