Content Security Policy is not configured
- Observed
- Responses did not include a Content-Security-Policy header.
- Impact
- CSP is the main browser defense against injected scripts — without it, one XSS bug exposes user sessions.
- Recommended action
- Add a CSP in report-only mode first, then enforce it.