On Fri, Feb 28, 2020 at 11:55 AM Martin Grigorov <mgrigo...@apache.org> wrote:
> > > On Fri, Feb 28, 2020 at 11:37 AM Andrea Del Bene <an.delb...@gmail.com> > wrote: > >> On Thu, Feb 27, 2020 at 1:03 PM Martin Grigorov <mgrigo...@apache.org> >> wrote: >> >> > >> > >> > I wanted to ask here whether we need an API that says whether CSP is >> > enabled or disabled. >> > For example UI libraries like Wicket Bootstrap & Wicket JQuery UI (and >> any >> > other) may use it to decide how to behave depending on the result. >> > Because at the moment there is no place for assumption - every library >> > should be updated to >> > assume that CSP is always enabled. >> > >> > >> > >> I think it would be nice to provide such API for those who will have >> problems adopting CSP. More generally I'd like to rework the CSP APIs in >> order to make them coherent with code conventions we have adopted with the >> other types of configurations . For example creating an >> Application.getCSPSettings() to access CSP configuration. >> > > +1 for this! > Done! > > >