LV 1.2.6 — Sicherheit
REQ-1.2.6-SECURITY
Proof level: TECHNICAL POC
Demonstrates
- ✓ CSP with per-request nonces (no script-src unsafe-inline)
- ✓ X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy
- ✓ HSTS on secure connections
- ✓ Craft's built-in CSRF protection (active by default on all POST forms)
Technical documentation
docs/security.md