Project

General

Profile

Actions

User story #26934

closed

Enable CSP on all pages and add tag to exclude a page

Added by Clark ANDRIANASOLO 2 months ago. Updated 7 days ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
UX impact:
It bothers me each time
Suggestion strength:
Want - This would make my life a lot easier but I can manage without
User visibility:
First impressions of Rudder
Effort required:
Medium
Name check:
To do
Fix check:
To do
Regression:
No

Description

We want CSP headers in all pages so the current directive to add CSP headers to a page in #25032 should be replaced by directives to ignore some pages, and CSP should be enabled on all pages by default


Subtasks 3 (0 open3 closed)

User story #26951: Plugins need CSP to be strict in Rudder but disabled in plugin pagesReleasedClark ANDRIANASOLOActions
Rudder plugins - User story #27002: Private plugins should have work with strict CSP headersReleasedClark ANDRIANASOLOActions
User story #27119: CSP headers for pages without scripts are always set with static nonceReleasedFrançois ARMANDActions

Related issues 2 (0 open2 closed)

Related to Rudder - Bug #25032: Use Content-Security-Policy strict headers in utilities pagesReleasedFrançois ARMANDActions
Related to API authorizations - Bug #27314: CSP violation in api accounts custom ACL selectionReleasedVéronique HAYAERTActions
Actions

Also available in: Atom PDF