-
-
Notifications
You must be signed in to change notification settings - Fork 795
Closed
Labels
1) Discussion ongoingIssue is opened and assigned but no clear proposal yetIssue is opened and assigned but no clear proposal yet4) proposal for reviewIssue contains clear proposal for add/change somethingIssue contains clear proposal for add/change something4b Major-reworkThese issues need to be part of a full chapter reworkThese issues need to be part of a full chapter rework_5.0 - prepThis needs to be addressed to prepare 5.0This needs to be addressed to prepare 5.0josh/elar
Description
Over time there is need to configure every kind of allow lists, like *-src and frame-ancestors for Content-Security-Policy (current requirements 14.4.3 and 14.4.7), allowed Origin's (14.2.3, 13.5.2, 14.5.3), allow list of resources or systems to which the server can send requests or load data/files from (12.6.1).
Problem to solve - if it's not documented, then sooner or later it's not clear, why there is some item in allow list and those may stay there even if thay are not needed (anymore).
Idea - create new requirement which requires those whitelists to be documented. Category probably 1.14.
Sjord
Metadata
Metadata
Assignees
Labels
1) Discussion ongoingIssue is opened and assigned but no clear proposal yetIssue is opened and assigned but no clear proposal yet4) proposal for reviewIssue contains clear proposal for add/change somethingIssue contains clear proposal for add/change something4b Major-reworkThese issues need to be part of a full chapter reworkThese issues need to be part of a full chapter rework_5.0 - prepThis needs to be addressed to prepare 5.0This needs to be addressed to prepare 5.0josh/elar