Skip to content
Ulrich Berntien edited this page Aug 16, 2020 · 1 revision

TWA-0216

Message

"Content-Security-Policy 'default-src' is missing'"

Explanation

The Content-Security-Policy is sent from the web server to the web browser in the HTTP header.

No default-src directive was found in the Content-Security-Policy HTTP response header field. The default-src directive can limit the sources of resources to include into the current web page.

Remediation

Set none as default-src for the Content-Security-Policy in the web server configuration.

See

Clone this wiki locally