-
-
Notifications
You must be signed in to change notification settings - Fork 639
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CSP] enhancements to example policy #181
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Wow, impressive PR, thanks a lot @Malvoz! 👍
As you may expect, some comments (inline). 😉
Do you want me to clarify that, here(?): server-configs-apache/src/security/content-security-policy.conf Lines 35 to 36 in a397654
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Technically LGTM.
May be relevant to add reflected-xss block
too, but not mandatory.
Fix #156
Also, with these changes the CSP
frame-ancestors
directive description now mentions the relation toX-Frame-Options
(https://w3c.github.io/webappsec-csp/#frame-ancestors-and-frame-options). Seems logicalX-Frame-Options
should say something aboutframe-ancestors
/CSP? I can probably do that tomorrow, really tired atm. :)