Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve & fix CSP #1528

Merged
merged 8 commits into from
Sep 27, 2022
Merged

Improve & fix CSP #1528

merged 8 commits into from
Sep 27, 2022

Conversation

ildyria
Copy link
Member

@ildyria ildyria commented Sep 25, 2022

After further inspection on the findings of @maggick , it appears that CSP was disabled...
This updates the config file and aims to fix it.

@ildyria ildyria added High Priority High priority issues Security Issue which may endanger the project labels Sep 25, 2022
@ildyria ildyria requested a review from a team September 25, 2022 12:34
@codecov
Copy link

codecov bot commented Sep 25, 2022

Codecov Report

Merging #1528 (05dbce3) into master (c0a90b7) will decrease coverage by 0.73%.
The diff coverage is n/a.

Additional details and impacted files

config/secure-headers.php Outdated Show resolved Hide resolved
config/secure-headers.php Outdated Show resolved Hide resolved
config/secure-headers.php Outdated Show resolved Hide resolved
config/secure-headers.php Outdated Show resolved Hide resolved
config/secure-headers.php Outdated Show resolved Hide resolved
config/secure-headers.php Outdated Show resolved Hide resolved
@nagmat84

This comment was marked as resolved.

@nagmat84

This comment was marked as resolved.

@ildyria ildyria added this to the 4.6.1 milestone Sep 25, 2022
@ildyria

This comment was marked as resolved.

Copy link
Collaborator

@nagmat84 nagmat84 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only one slight change, but otherwise it looks good to me. I haven't tested it again, because I am on a business trip and I am reading and typing from my smartphone. So I also skimmed the changes only. But I assume that all issues have been addressed. Hence, I don't want to block this PR with my previous review any longer.

config/secure-headers.php Outdated Show resolved Hide resolved
@ildyria ildyria merged commit fd445f6 into master Sep 27, 2022
@ildyria ildyria deleted the CSP branch September 27, 2022 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
High Priority High priority issues Security Issue which may endanger the project
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants