element-hq / element-hq/element-web
Content Security Policy: add `base-uri`
Open
Security
T-Enhancement
- Dominant language
- TypeScript
- Stars
- 13.5k
- Forks
- 2.8k
- PR merge metrics
- PR metrics pending
Description
Right now https://observatory.mozilla.org/ gives Rank B, adding `base-uri 'none'` increases it to `A+`
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/base-uri
Contributor guide
Research direction
No file or test is named. Start by locating where the Content-Security-Policy response header is configured, then consult the linked MDN description and verify the Observatory result; done means the header includes base-uri 'none' and the change is covered by the repository's relevant checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100