Appendix C - Security : Content-Security-Policy
  

Content-Security-Policy

The HTTP Content-Security-Policy response header allows web site administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints. This helps guard against cross-site scripting attacks ( XSS).

Syntax

Content-Security-Policy: <policy-directive>; <policy-directive>
 

Orchestra default configuration

Content-Security-Policy: *