The Security Header 96% of Sites Still Don’t Set
Every page a browser loads can, by default, be asked to hand a visitor’s camera, microphone, or location to any script running on it, including scripts your site didn’t write and doesn’t control. Almost nobody explicitly closes that door. What Permissions-Policy actually controls Permissions-Policy is a response header that declares which browser features and APIs […]
Read more →

