Skip to content

discussion/new requirement: inventory/documentation for "allow listed" sources and communications #993

@elarlang

Description

@elarlang

Over time there is need to configure every kind of allow lists, like *-src and frame-ancestors for Content-Security-Policy (current requirements 14.4.3 and 14.4.7), allowed Origin's (14.2.3, 13.5.2, 14.5.3), allow list of resources or systems to which the server can send requests or load data/files from (12.6.1).

Problem to solve - if it's not documented, then sooner or later it's not clear, why there is some item in allow list and those may stay there even if thay are not needed (anymore).

Idea - create new requirement which requires those whitelists to be documented. Category probably 1.14.

Metadata

Metadata

Assignees

Labels

1) Discussion ongoingIssue is opened and assigned but no clear proposal yet4) proposal for reviewIssue contains clear proposal for add/change something4b Major-reworkThese issues need to be part of a full chapter rework_5.0 - prepThis needs to be addressed to prepare 5.0josh/elar

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions