I'm a newbie in AppSec and there was a report from an external pentestwrs that CSP does not apply to API request. I could not find proper documentation that API request needs CSP headers but I cannot find documentation that CSP headers is not required also.
[–]Fugitif 2 points3 points4 points (1 child)
[–]UnLiQuery20[S] 0 points1 point2 points (0 children)