|
||||||||
|
This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators. For more information on JIRA, see: http://www.atlassian.com/software/jira |
||||||||
You received this message because you are subscribed to the Google Groups "Jenkins Issues" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
For more options, visit https://groups.google.com/d/optout.

That indeed looks like the right header to use going forward. http://www.w3.org/TR/CSP/#content-security-policy-header-field notes that multiple such headers are all enforced, but that should not force the introduction of an API since st:setHeader overrides an existing single header.