How to set Content Security Policy in an ADF application.
Got feedback from security team that ADF application should have CSP and I google to understand about the same.
Came across with an article from oracle which says 'Oracle recommendation with regards to the response header "Context-Security-Policy" is to add unsafe-eval and unsafe-inline to CSP headers.'
I have 2 questions where I need community help regarding the same.
- Adding unsafe-eval and unsafe-inline is it helpful as CSP.
- How exactly CSP can be defined in an ADF application.
ADF : 12.2.1.4 , Weblogic server 12c