Fixed security issue and noscript iframe

This commit is contained in:
alexjanousekGSA
2025-04-07 14:45:28 -04:00
parent 82934daa02
commit b5675e586e
3 changed files with 27 additions and 173 deletions

View File

@@ -169,6 +169,10 @@ def _csp(config):
def create_app(application):
@application.after_request
def add_csp_header(response):
response.headers['Content-Security-Policy'] = "frame-src https://www.googletagmanager.com"
return response
# @application.context_processor
# def inject_feature_flags():
# this is where feature flags can be easily added as a dictionary within context