github / github/secure_headers

Set default `frame-ancestors` on default Content-Security-Policy

Open
#532 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Ruby
Stars
3.2k
Forks
253
Avg merge
19h 11m
Merged PRs (30d)
1

Description

We should consider setting a default `frame-ancestors` directive for the Content Security Policy. The [`frame-ancestors`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors) directive is the new iteration of the X-Frame-Options header, and as such setting a directive in both spots might be prudent.

https://github.com/github/secure_headers/blob/b134eef07d3741b4bd0769b863961b41af5df57d/lib/secure_headers/headers/content_security_policy_config.rb#L97

Since our default XFO policy is `sameorigin`, if we decide to take upon this task, we should set the default `frame-ancestors` value to be `self`.

Some counterpoints: setting both the `X-Frame-Options` and the `frame-ancestors` directive will cause the XFO header to be overriden by the frame-ancestors directive. This means that if a user is trying to change some framing functionality, and only changes the XFO header, they might be confused as to why the functionality didn't actually change.

Contributor guide

Open the contributing guide

Research direction

Start with lib/secure_headers/headers/content_security_policy_config.rb around the linked default policy. Review how the existing sameorigin X-Frame-Options default is configured and consider the stated interaction with frame-ancestors. Done means resolving whether the default should include frame-ancestors self and implementing the decision without leaving the two framing controls misleadingly inconsistent.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.