-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
There is a bunch of new security headers incoming, specifically COOP, COEP, CORP and CORB. We need to investigate which are appropriate to our family of sites.
Source: https://scotthelme.co.uk/coop-and-coep/
- Cross Origin Opener Policy (COOP) MDN
- Cross Origin Embedder Policy (COEP) MDN
- Cross Origin Resource Policy (CORP) MDN
Note that also Cross Origin Read Blocking (CORB) is mentioned, this depends on rules such as Access-Control-Allow-Origin: * not being used, which we currently do use (although I need to remember why we set this - there was a reason). EDIT: this was the reason.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels