Function: pageCsp()
> pageCsp(options?): string
Defined in: http/src/html.ts:64
A locked-down, route-scoped CSP for a self-contained HTML page: everything denied by default; inline scripts allowed ONLY by hash; styles inline (style-src 'unsafe-inline' — hash sources cannot cover style="" attributes); fetch restricted to 'self' plus the given origins. Set it on the route's response so it overrides the app-wide default from securityPlugin for that page only.
Parameters
options?
PageCspOptions = {}
Returns
string