
Before we enable new Content Security Policy on a working site, we need to make sure it will not break any existing flows. Report-Only mode solves that problem. It lets browsers report CSP violations without enforcing the rules or blocking…
View original source — Hacker Noon ↗


