Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upAdding Content-Security-Policy (CSP) to website to protect users against XSS attacks #2756
Comments
andrewdavidwong
added
C: website
enhancement
labels
Apr 18, 2017
andrewdavidwong
added this to the
Documentation/website milestone
Apr 18, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
andrewdavidwong
Apr 18, 2017
Member
Cool! Thanks for pointing this out.
I think we'd just want 'self' for everything. Is there an easy way to do that for all directives, or must we specify each one?
CC @marmarek
|
Cool! Thanks for pointing this out. I think we'd just want CC @marmarek |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
marmarek
Apr 18, 2017
Member
- https://www.qubes-os.org/statistics/ loads image from https://tools.qubes-os.org/
- https://www.qubes-os.org/video-tours/ loads youtube
There may be more. Hmm, what is this?! Not so careful grep doesn't reveal anything else.
There may be more. Hmm, what is this?! Not so careful grep doesn't reveal anything else. |
andrewdavidwong
added
the
help wanted
label
Mar 18, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
ghost commentedApr 18, 2017
This CSP can be easily added in github pages as explained here and would add more security to the site by protecting users against XSS attacks.