Skip to content

Evaluate Canonical value of security.txt ? #772

Closed
@baknu

Description

@baknu

Currently we do not check the value of the Canonical fields, because we find that its meaning is unclear in the security.txt specification. The latter is only the case when redirects are involved.

This issue is to get more clearity on its meaning when redirects are invloved, and also to discuss if and how we can add a check for this.

Note 1: Clarification question was already asked on securitytxt/security-txt#217
Note 2: The sectxt parser now uses the following interpretation: ""Web URI where security.txt is located must match with a 'Canonical' field. In case of redirecting either the first or last web URI of the redirect chain must match.""

Metadata

Metadata

Assignees

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions