Closed
Description
Description
Perhaps this is not a documentation issue, or rather, this document in particular.
As we discovered in pen testing of our Blazor server-side app, we were missing CSP headers. As I put them in, I am running into a BIG problem because, as much of the Blazor sample documentation indicates, I used inline script all over the place. If I have to hash every single place in the app where there is code, I can't imagine the size of the csp header for all the hashes I'll need.
I must be missing something...or there is a fundamental flaw in Blazor/razor re: security and XSS.
[Enter feedback here]
Page URL
Content source URL
Document ID
6e0b5c52-90a1-5ca6-bfad-df33a8beae6c
Article author
Metadata
Metadata
Assignees
Type
Projects
Status
Done