Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP if SSL is in use... #106

Open
tom-lp-at opened this issue Nov 7, 2022 · 0 comments
Open

CSP if SSL is in use... #106

tom-lp-at opened this issue Nov 7, 2022 · 0 comments

Comments

@tom-lp-at
Copy link

Dear Feuzeu,
i have a strange problem and can not figure out where it comes from.
I write my application in CI 4.2.7 and developed the hole time without SSL (local http only). After i deployed the application in his first state, i recognized that "Content-Security-Header" are send. But in CI and on NGinx is no injection of CSP Headers enabled. If i do, the CSP-Header are twice...
The strange thing :
grafik
In this CSP is jaxon-php in the list, so i assume that the SPF is injected by jaxon-php. I search around in the source of jaxon-php but can´t find any "mystery" thing´s that happens...
Do you have a clue where the CSP is come from?

kr Tom

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant