Project

General

Profile

Actions

Bug #25032

open

Use Content-Security-Policy strict headers in utilities pages

Added by Clark ANDRIANASOLO 29 days ago. Updated 8 days ago.

Status:
Pending release
Priority:
N/A
Category:
Security
Target version:
Severity:
Minor - inconvenience | misleading | easy workaround
UX impact:
User visibility:
Getting started - demo | first install | Technique editor and level 1 Techniques
Effort required:
Small
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

We have added the necessary boilerplate in #24015 to include HTML pages to be loaded with strict CSP headers, and applied it to the healtcheck page.

We now need to include these headers in other Utilities pages within Rudder : archives, event logs


Related issues 1 (0 open1 closed)

Related to Rudder - Bug #24015: Use Content-Security-Policy strict headersReleasedClark ANDRIANASOLOActions
Actions #1

Updated by Clark ANDRIANASOLO 29 days ago

  • Description updated (diff)
Actions #2

Updated by Clark ANDRIANASOLO 29 days ago

  • Related to Bug #24015: Use Content-Security-Policy strict headers added
Actions #3

Updated by Clark ANDRIANASOLO 29 days ago

  • Status changed from New to In progress
Actions #4

Updated by Clark ANDRIANASOLO 11 days ago

  • Subject changed from Use Content-Security-Policy strict headers in web pages to Use Content-Security-Policy strict headers in utilities pages
  • Description updated (diff)
Actions #5

Updated by Clark ANDRIANASOLO 11 days ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Clark ANDRIANASOLO to François ARMAND
  • Pull Request set to https://github.com/Normation/rudder/pull/5764
Actions #6

Updated by Clark ANDRIANASOLO 8 days ago

  • Status changed from Pending technical review to Pending release
Actions

Also available in: Atom PDF