github / github/secure_headers

Set default `frame-ancestors` on default Content-Security-Policy

Abierto
#532 1 comentario 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Ruby
Estrellas
3.2k
Forks
253
Merge medio
19 h 11 min
PR fusionados (30 d)
1

Descripción

We should consider setting a default `frame-ancestors` directive for the Content Security Policy. The [`frame-ancestors`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors) directive is the new iteration of the X-Frame-Options header, and as such setting a directive in both spots might be prudent.

https://github.com/github/secure_headers/blob/b134eef07d3741b4bd0769b863961b41af5df57d/lib/secure_headers/headers/content_security_policy_config.rb#L97

Since our default XFO policy is `sameorigin`, if we decide to take upon this task, we should set the default `frame-ancestors` value to be `self`.

Some counterpoints: setting both the `X-Frame-Options` and the `frame-ancestors` directive will cause the XFO header to be overriden by the frame-ancestors directive. This means that if a user is trying to change some framing functionality, and only changes the XFO header, they might be confused as to why the functionality didn't actually change.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start with lib/secure_headers/headers/content_security_policy_config.rb around the linked default policy. Review how the existing sameorigin X-Frame-Options default is configured and consider the stated interaction with frame-ancestors. Done means resolving whether the default should include frame-ancestors self and implementing the decision without leaving the two framing controls misleadingly inconsistent.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
ruby
Área
security
Tipo de issue
Nueva funcionalidad
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
38/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.