angular / angular/angular-cli

Make autoCSP configurable

Ouverte
#29,615 9 commentaires 6 réactions 0 personnes assignées Voir sur GitHub
angular/build:application area: @angular/build
Langage dominant
TypeScript
Étoiles
27k
Forks
11.8k
Merge moyen
14 h 23 min
PR mergées (30 j)
162

Description

### Command

build

### Description

Great to see autoCSP property cause looks like it's the only way to go with PWA.
Please could you make possible to add extra options to generated CSP ? I'd love to specify for example `default-src`, `img-src` e.t.c.

### Describe the solution you'd like

Make it somehow configurable:

"autoCsp": {
"default-src": "'self'",
"img-src": "* data: blob:",
"media-src": "'self' data:"
}

### Describe alternatives you've considered

A header still will be needed for frame-ancestors to add (for example in nginx):

add_header Content-Security-Policy "frame-ancestors 'none'";

It works nicely in conjuction with autoCSP and I can even specify

add_header Content-Security-Policy "frame-ancestors 'none'; media-src 'self' data:";

The issue here is that if I add `default-src`

add_header Content-Security-Policy "default-src 'self'; frame-ancestors 'none'; media-src 'self' data:";

Angular app will be broken because the least permissive policy (this one) wins.
To workaround it I will have to specify each case separately here `worker-src; frame-src` e.t.c but _do not_ specify `script-src` which will make it enormous and hard to maintain.
I would love to specify them in index.html directly

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par la commande de build de la CLI et le chemin existant de génération d’autoCSP. Suivez la manière dont la Content-Security-Policy générée est assemblée, puis vérifiez que les directives demandées peuvent être configurées et que la politique résultante fonctionne avec les cas nginx et PWA indiqués.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
angular, typescript
Domaine
build-system, security
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.