This repository was archived by the owner on Nov 4, 2024. It is now read-only.

Description
Steps:
- Scan page: https://shop.rockwool.com
Observation:
- Page scores 120 with most CSP directives listed as "none".
Expectation:
- Page should score 110, as there are more directives in tag. They are analyzed by code, but discarded.
Problem appeared in commit a422b3a - when I check out master before this commit, the combined policy is analyzed properly.
CSP header data:
upgrade-insecure-requests; frame-ancestors 'self'
@april