alt="">
`
app.get('/', function(req, res) {
res.set('Content-Security-Policy', "img-src...我们尝试修改一下该策略让 httpbin 的资源生效
app.get('/', function(req, res) {
+ res.set('Content-Security-Policy', img-src...function(req, res) {
+ res.set('Content-Security-Policy', "script-src https://lib.baomitu.com 'self'; img-src...img-src: 限制图片和图标源
manifest-src : 限制 application manifest 文件源。...application/csp-report'}))
app.get('/', function(req, res) {
+ res.set('Content-Security-Policy', "img-src