Pain point · Permissions & security · Blocks work
Default Content Security Policy is too permissive
1 source thread · first seen 2023-01
Summary
Keycloak's default CSP is not locked down enough to protect against XSS and one header applies to every part of the product.
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“The default Content Security Policy (CSP) used by Keycloak is not locked down enough”