github / github/secure_headers
Validation on plugin-types does not allow for the empty directive
Đang mở
- Ngôn ngữ chính
- Ruby
- Star
- 3.2k
- Fork
- 253
- Merge trung bình
- 19 giờ 11 phút
- Pull request đã merge (30 ngày)
- 1
Mô tả
# Bugs
> Note: The plugin-types grammar allows for an empty directive value in which case all instantions of embed and object will fail.
https://w3c.github.io/webappsec-csp/#directive-plugin-types
We validate it must match something like `application/pdf` which is not correct.
### Expected outcome
Describe what you expected to happen
`plugin_types` should allow for an empty directive. Sending an empty array omits the directive. Sending `none` is not allowed by validation. An array of empty strings doesn't work either (validation)
### Actual outcome
Configuration errors when trying to do the right thing
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.