Both server blocks were missing Content-Security-Policy and Permissions-Policy entirely (dexarmarket.ru already had them). This is defense-in-depth against XSS, not a fix for the underlying issue: the customer session cookie is still non-HttpOnly and JS-readable, which only a backend Set-Cookie change can close (BACKEND-API-REFERENCE.md §12). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
8.1 KiB
8.1 KiB