diff --git a/app.py b/app.py index bcaaab1..fbc08a4 100644 --- a/app.py +++ b/app.py @@ -13,6 +13,25 @@ from api.sessions import sessions_bp from utils.exclusion_rules import load_rules, resolve_exclusion_rules_path +# Content-Security-Policy for all Flask responses. 'unsafe-inline' in style-src is +# required because highlight.js themes apply inline styles; can be tightened with +# nonces later. script-src lists cdnjs only — keep in sync with SRI +