Harden CSRF/CSP and add hash version upgrades
This commit is contained in:
1
SPEC.md
1
SPEC.md
@@ -41,3 +41,4 @@ Help a small Discord group (4–8 players) pick a co-op game via phased flow:
|
||||
## Non-functional
|
||||
- Desktop + mobile friendly
|
||||
- Runs on IIS; SQLite via EF Core
|
||||
- Browser security baseline: strict CSP (no inline styles, no insecure image origins) and same-origin protection for authenticated mutating API requests
|
||||
|
||||
Reference in New Issue
Block a user