Add Enterprise Search Host to form-action
CSP directive
#206458
Labels
blocked
enhancement
New value added to drive a business result
Feature:Security/CSP
Platform Security - Content Security Policy
Team:Security
Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
Our
form-action
CSP directive is currently set toself
. We should add the enterprise search host, if configured viaxpack.enterpriseSearch.host
(kibana/x-pack/solutions/search/plugins/enterprise_search/server/index.ts
Line 27 in d62566a
form-action
is set as a "report only" directive. Adding this additional host will reduce the noise in our reports, and boost our confidence in promoting this to an enforced directive.Blocked on portions of #181812
The text was updated successfully, but these errors were encountered: