Actions
User story #26951
closedUser story #26934: Enable CSP on all pages and add tag to exclude a page
Plugins need CSP to be strict in Rudder but disabled in plugin pages
Status:
Released
Priority:
N/A
Assignee:
Category:
Web - Maintenance
Target version:
Pull Request:
UX impact:
Suggestion strength:
User visibility:
First impressions of Rudder
Effort required:
Small
Name check:
To do
Fix check:
To do
Regression:
No
Description
In parent, strict CSP headers are enabled on all pages and need to be present for scripts added by some plugins, e.g. to display something from the plugin the login page, or in the navbar.
But the plugins pages themselves have additional pages, which can be later migrated to include CSP headers
Updated by Clark ANDRIANASOLO 2 months ago
- Status changed from New to In progress
Updated by Clark ANDRIANASOLO 2 months ago
- Status changed from In progress to Pending technical review
- Pull Request set to https://github.com/Normation/rudder-plugins/pull/837
Updated by Clark ANDRIANASOLO about 2 months ago
- Status changed from Pending technical review to Pending release
Applied in changeset rudder-plugins|42a18f38aaa5d07904f80688e16ed5e1445b08b2.
Updated by Clark ANDRIANASOLO 13 days ago
- Related to Bug #27314: CSP violation in api accounts custom ACL selection added
Updated by Alexis Mousset 7 days ago
- Status changed from Pending release to Released
This bug has been fixed in Rudder plugin api-authorizations v9.0.0.alpha1-2.2
Updated by Alexis Mousset 7 days ago
This bug has been fixed in Rudder plugin branding v9.0.0.alpha1-2.2
Updated by Alexis Mousset 7 days ago
This bug has been fixed in Rudder plugin change-validation v9.0.0.alpha1-2.4
Updated by Alexis Mousset 7 days ago
This bug has been fixed in Rudder plugin datasources v9.0.0.alpha1-2.4
Actions