Skip to content

Conversation

@plaintextcity
Copy link

The original version only adds security headers to text/html. That's good, but it also only sanitizes the headers for text/html, always be sanitizing!

The original version only adds security headers to text/html.  That's good, but it also only sanitizes the headers for text/html, and we should always be sanitizing!
@ScottHelme
Copy link
Contributor

I think this was covered in a previous PR merge, can you confirm?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants