Besides using xss api is there a recommended way of implementing content security policy headers in AEM?
Content Security Policies and the Experience Cloud ID Service
Content Security Policy (CSP) - HTTP | MDN
In the above links and recommendations, whitelisting urls and scripts is a standard way of implementing CSP but is there a recommendation for implementing a CSP in AEM and would like to know if someone implemented and help me in implementing one.
-Sanjay
