Consider applying strict CSP to API endpoints #6187

Open
opened 2026-08-19 18:43:32 +02:00 by danb · 0 comments
Owner

Description

Would help in scenarios where API responses contain potentially dangerous data (which should never be the case unless other vulnerabilities exist) which could be exploited via direct access/use. Really just a hardening layer. Need to double check the potential impact.

### Description Would help in scenarios where API responses contain potentially dangerous data (which should never be the case unless other vulnerabilities exist) which could be exploited via direct access/use. Really just a hardening layer. Need to double check the potential impact.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
bookstack/bookstack#6187
No description provided.