A critical vulnerability was discovered in React Server Components (Next.js). Our systems remain protected but we advise to update packages to newest version. Learn More.
AI OnAI Off
A critical vulnerability was discovered in React Server Components (Next.js). Our systems remain protected but we advise to update packages to newest version. Learn More.
Have you followed this guide https://world.optimizely.com/documentation/developer-guides/CMS/security/content-security-policy/? You might also have to tweak your policy depending on if the URL is your frontend or the CMS.
After reviewing security recommendations, Im trying to add some security headers to my site. Two headers in particualr are causing problems:
Content-Security-Policy
X-Content-Type-Options
I can set them to work on the fron end of the site but they break the CMS. How do I set these so they dont get used in the CMS?