The HelcimPay modal loads from secure.helcim.app, but the CSP only listed myposjs.helcim.com (script/connect) and secure.helcim.com (frame, likely a stale typo). Add secure.helcim.app to script-src, connect-src, and frame-src so the join flow's payment modal can load. |
||
|---|---|---|
| .. | ||
| csrf.test.js | ||
| rate-limit.test.js | ||
| security-headers.test.js | ||