Make autoCSP configurable
- Linguagem predominante
- TypeScript
- Estrelas
- 27k
- Forks
- 11.8k
- Merge médio
- 14h 23min
- PRs com merge (30d)
- 162
Descrição
### Command
build
### Description
Great to see autoCSP property cause looks like it's the only way to go with PWA.
Please could you make possible to add extra options to generated CSP ? I'd love to specify for example `default-src`, `img-src` e.t.c.
### Describe the solution you'd like
Make it somehow configurable:
"autoCsp": {
"default-src": "'self'",
"img-src": "* data: blob:",
"media-src": "'self' data:"
}
### Describe alternatives you've considered
A header still will be needed for frame-ancestors to add (for example in nginx):
add_header Content-Security-Policy "frame-ancestors 'none'";
It works nicely in conjuction with autoCSP and I can even specify
add_header Content-Security-Policy "frame-ancestors 'none'; media-src 'self' data:";
The issue here is that if I add `default-src`
add_header Content-Security-Policy "default-src 'self'; frame-ancestors 'none'; media-src 'self' data:";
Angular app will be broken because the least permissive policy (this one) wins.
To workaround it I will have to specify each case separately here `worker-src; frame-src` e.t.c but _do not_ specify `script-src` which will make it enormous and hard to maintain.
I would love to specify them in index.html directly
Guia de contribuição
Direção de pesquisa
Comece com o comando de build da CLI e o caminho existente de geração do autoCSP. Rastreie como a Content-Security-Policy gerada é montada e, em seguida, verifique se as diretivas solicitadas podem ser configuradas e se a política resultante funciona com os casos indicados de nginx e PWA.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- angular, typescript
- Domínio
- build-system, security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Estagnada
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 45/100