Project

General

Profile

Actions

User story #26951

closed

User story #26934: Enable CSP on all pages and add tag to exclude a page

Plugins need CSP to be strict in Rudder but disabled in plugin pages

Added by Clark ANDRIANASOLO 2 months ago. Updated 7 days ago.

Status:
Released
Priority:
N/A
Category:
Web - Maintenance
Target version:
UX impact:
Suggestion strength:
User visibility:
First impressions of Rudder
Effort required:
Small
Name check:
To do
Fix check:
To do
Regression:
No

Description

In parent, strict CSP headers are enabled on all pages and need to be present for scripts added by some plugins, e.g. to display something from the plugin the login page, or in the navbar.

But the plugins pages themselves have additional pages, which can be later migrated to include CSP headers


Related issues 1 (0 open1 closed)

Related to API authorizations - Bug #27314: CSP violation in api accounts custom ACL selectionReleasedVéronique HAYAERTActions
Actions #1

Updated by Clark ANDRIANASOLO 2 months ago

  • Status changed from New to In progress
Actions #2

Updated by Clark ANDRIANASOLO 2 months ago

  • Status changed from In progress to Pending technical review
  • Pull Request set to https://github.com/Normation/rudder-plugins/pull/837
Actions #3

Updated by Clark ANDRIANASOLO about 2 months ago

  • Status changed from Pending technical review to Pending release
Actions #4

Updated by Clark ANDRIANASOLO 13 days ago

  • Related to Bug #27314: CSP violation in api accounts custom ACL selection added
Actions #5

Updated by Alexis Mousset 7 days ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder plugin api-authorizations v9.0.0.alpha1-2.2

Actions #6

Updated by Alexis Mousset 7 days ago

This bug has been fixed in Rudder plugin branding v9.0.0.alpha1-2.2

Actions #7

Updated by Alexis Mousset 7 days ago

This bug has been fixed in Rudder plugin change-validation v9.0.0.alpha1-2.4

Actions #8

Updated by Alexis Mousset 7 days ago

This bug has been fixed in Rudder plugin datasources v9.0.0.alpha1-2.4

Actions

Also available in: Atom PDF