Project

General

Profile

Actions

User story #26934

open

Enable CSP on all pages and add tag to exclude a page

Added by Clark ANDRIANASOLO 8 days ago. Updated 5 days ago.

Status:
Pending technical review
Priority:
N/A
Category:
Security
Target version:
UX impact:
It bothers me each time
Suggestion strength:
Want - This would make my life a lot easier but I can manage without
User visibility:
First impressions of Rudder
Effort required:
Medium
Name check:
To do
Fix check:
To do
Regression:
No

Description

We want CSP headers in all pages so the current directive to add CSP headers to a page in #25032 should be replaced by directives to ignore some pages, and CSP should be enabled on all pages by default


Subtasks 1 (1 open0 closed)

User story #26951: Plugins need CSP to be strict in Rudder but disabled in plugin pagesPending technical reviewClark ANDRIANASOLOActions

Related issues 1 (0 open1 closed)

Related to Rudder - Bug #25032: Use Content-Security-Policy strict headers in utilities pagesReleasedFrançois ARMANDActions
Actions #1

Updated by Clark ANDRIANASOLO 8 days ago

  • Related to Bug #25032: Use Content-Security-Policy strict headers in utilities pages added
Actions #2

Updated by Clark ANDRIANASOLO 5 days ago

  • Status changed from New to Pending technical review
  • Assignee changed from Clark ANDRIANASOLO to François ARMAND
  • Pull Request set to https://github.com/Normation/rudder/
Actions #3

Updated by Clark ANDRIANASOLO 5 days ago

  • Pull Request changed from https://github.com/Normation/rudder/ to https://github.com/Normation/rudder/6394
Actions #4

Updated by Clark ANDRIANASOLO 5 days ago

  • Pull Request changed from https://github.com/Normation/rudder/6394 to https://github.com/Normation/rudder/pull/6394
Actions #5

Updated by Clark ANDRIANASOLO 5 days ago

  • Subtask #26951 added
Actions

Also available in: Atom PDF