Skip to content

Commit

Permalink
docs: makes note of HTTP header CSP usage with file://
Browse files Browse the repository at this point in the history
  • Loading branch information
Slapbox authored and zcbenz committed Nov 28, 2018
1 parent 41c2685 commit ee294c8
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions docs/tutorial/security.md
Expand Up @@ -374,8 +374,10 @@ session.defaultSession.webRequest.onHeadersReceived((details, callback) => {

### CSP Meta Tag

CSP's preferred delivery mechanism is an HTTP header. It can be useful, however,
to set a policy on a page directly in the markup using a `<meta>` tag:
CSP's preferred delivery mechanism is an HTTP header, however it is not possible
to use this method when loading a resource using the `file://` protocol. It can
be useful in some cases, such as using the `file://` protocol, to set a policy
on a page directly in the markup using a `<meta>` tag:

```html
<meta http-equiv="Content-Security-Policy" content="default-src 'none'">
Expand Down

0 comments on commit ee294c8

Please sign in to comment.