David Anderson db800ddeac cmd/derper: set Content-Security-Policy on DERPs.
It's a basic "deny everything" policy, since DERP's HTTP
server is very uninteresting from a browser POV. But it
stops every security scanner under the sun from reporting
"dangerously configured" HTTP servers.

Updates tailscale/corp#3119

Signed-off-by: David Anderson <danderson@tailscale.com>
2021-11-26 11:00:44 -08:00
..
2021-10-28 16:02:11 -07:00
2021-05-16 14:52:00 -07:00
2021-09-14 13:21:55 -07:00
2021-11-23 12:05:32 -08:00