request('GET', '/admin'); $csp = $client->getResponse()->headers->get('Content-Security-Policy'); self::assertNotNull($csp, 'admin SPA response must set a Content-Security-Policy'); self::assertStringContainsString("default-src 'self'", $csp); self::assertStringContainsString("object-src 'none'", $csp); self::assertStringContainsString("frame-ancestors 'none'", $csp); } public function testNonAdminResponseDoesNotGetTheAdminCsp(): void { $client = static::createClient(); $client->request('GET', '/api/v1/doctors'); $csp = (string) $client->getResponse()->headers->get('Content-Security-Policy'); // The admin policy allows scripts from 'self'; the API policy is default-src 'none'. // Either way the admin-specific script-src must not leak onto /api. self::assertStringNotContainsString("script-src 'self'", $csp); } }