Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP warnings in real operation #1999

Closed
sleidig opened this issue Sep 14, 2023 · 3 comments
Closed

CSP warnings in real operation #1999

sleidig opened this issue Sep 14, 2023 · 3 comments
Assignees

Comments

@sleidig
Copy link
Member

sleidig commented Sep 14, 2023

After deploying the CSP (report-only), some content is still triggering warnings and not properly whitelisted in our default CSP:

@sleidig sleidig moved this from Triage to Priority (Core Team) in All Tasks & Issues Sep 18, 2023
@sleidig sleidig self-assigned this Sep 18, 2023
@TheSlimvReal
Copy link
Collaborator

One problem is that the index.html script hash has not been correctly updated. How can this be done?

@sleidig
Copy link
Member Author

sleidig commented Jan 22, 2024

I documented this here in den Developer Docs "Security" Concept (happy for suggestions about a better place): https://aam-digital.github.io/ndb-core/documentation/additional-documentation/concepts/security.html

@TheSlimvReal
Copy link
Collaborator

The instructions dont seem to work on all browsers (this is from Chrome on Mac, Safari seems to show even less info)
Screenshot 2024-01-22 at 09 20 49

@sleidig sleidig moved this from Priority (Core Team) to In Progress in All Tasks & Issues Jan 22, 2024
@sleidig sleidig closed this as completed Jan 25, 2024
@github-project-automation github-project-automation bot moved this from In Progress to Done in All Tasks & Issues Jan 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Archived in project
Development

No branches or pull requests

2 participants