github / github/secure_headers

Support CSP "double policies"

Open
#476 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Ruby
Stars
3.2k
Forks
253
Avg merge
19h 11m
Merged PRs (30d)
1

Description

CSP double policies enable setups that are not possible with just one CSP. When a browser sees a response with multiple CSP headers (or a single CSP header split via commas ","), the browser will enforce *all* those policies.

One common use case here is to support `strict-dynamic` with nonces and a URI allowlist, which isn't possible with a single `script-src` directive.

There's more information in this talk: https://youtu.be/_L06HetskC4?t=1754.

Contributor guide

Open the contributing guide

Research direction

The issue does not name files, tests, or entry points. Start by locating the CSP header generation and reviewing the linked talk and browser behavior for multiple policies; done means supporting multiple CSP policies or comma-split CSP values while enforcing each policy as browsers do.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.