i want to disable the CSP - app.use(helmet.contentSecurityPolicy()) because it blocks any inline-scripts. the hash and nonce solutions (https://content-security-policy.com/examples/allow-inline-script/) are too much overkill for my app.
is the xss-clean package or others solutions are enough to get a regular-moderate security?
thanks :)
You have complete control using the
helmetmiddleware you mentioned.The reference docs are clear about setting up your CSP.
Once set, you can always evaluate the strength your CSP with a validator such as this one.
From the docs:
You can set the policy when you load up 'helmet` by following the instructions in the documentation.
For example, here is an example configuration: