github / github/secure_headers

Validation on plugin-types does not allow for the empty directive

Open
#448 1 comment 1 reaction 2 assignees Claimed by @fletchto99 View on GitHub
Dominant language
Ruby
Stars
3.2k
Forks
253
Avg merge
19h 11m
Merged PRs (30d)
1

Description

# Bugs

> Note: The plugin-types grammar allows for an empty directive value in which case all instantions of embed and object will fail.

https://w3c.github.io/webappsec-csp/#directive-plugin-types

We validate it must match something like `application/pdf` which is not correct.

### Expected outcome

Describe what you expected to happen

`plugin_types` should allow for an empty directive. Sending an empty array omits the directive. Sending `none` is not allowed by validation. An array of empty strings doesn't work either (validation)

### Actual outcome

Configuration errors when trying to do the right thing

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.