Skip to content

Conversation

@BadgerOps
Copy link
Owner

@BadgerOps BadgerOps commented Feb 3, 2026

Summary

  • add CSP and standard security headers for Firebase Hosting
  • keep existing cache-control headers intact

Testing

Testing plan

npm run dev and load the app in a browser.
Open DevTools Console and confirm no CSP violations on initial load and common flows (login, documents, surveys).
Verify that documents still download from Firebase Storage and profile photos (Google user content) still render.
In the Network tab, confirm response headers include CSP, X-Content-Type-Options, Referrer-Policy, and X-Frame-Options.

@github-actions
Copy link

github-actions bot commented Feb 3, 2026

🚀 Preview Deployment

Your preview is ready!

Preview URL: https://wots-app-484617--pr-45-fmrypx00.web.app

This preview will expire in 7 days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant