github / github/secure_headers
Support CSP "double policies"
- Dominant language
- Ruby
- Stars
- 3.2k
- Forks
- 253
- Avg merge
- 19h 11m
- Merged PRs (30d)
- 1
Description
CSP double policies enable setups that are not possible with just one CSP. When a browser sees a response with multiple CSP headers (or a single CSP header split via commas ","), the browser will enforce *all* those policies.
One common use case here is to support `strict-dynamic` with nonces and a URI allowlist, which isn't possible with a single `script-src` directive.
There's more information in this talk: https://youtu.be/_L06HetskC4?t=1754.
Contributor guide
Research direction
The issue does not name files, tests, or entry points. Start by locating the CSP header generation and reviewing the linked talk and browser behavior for multiple policies; done means supporting multiple CSP policies or comma-split CSP values while enforcing each policy as browsers do.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ruby
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100