github / github/secure_headers
Set default `frame-ancestors` on default Content-Security-Policy
- Linguagem predominante
- Ruby
- Estrelas
- 3.2k
- Forks
- 253
- Merge médio
- 19h 11min
- PRs com merge (30d)
- 1
Descrição
We should consider setting a default `frame-ancestors` directive for the Content Security Policy. The [`frame-ancestors`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors) directive is the new iteration of the X-Frame-Options header, and as such setting a directive in both spots might be prudent.
https://github.com/github/secure_headers/blob/b134eef07d3741b4bd0769b863961b41af5df57d/lib/secure_headers/headers/content_security_policy_config.rb#L97
Since our default XFO policy is `sameorigin`, if we decide to take upon this task, we should set the default `frame-ancestors` value to be `self`.
Some counterpoints: setting both the `X-Frame-Options` and the `frame-ancestors` directive will cause the XFO header to be overriden by the frame-ancestors directive. This means that if a user is trying to change some framing functionality, and only changes the XFO header, they might be confused as to why the functionality didn't actually change.
Guia de contribuição
Direção de pesquisa
Comece por lib/secure_headers/headers/content_security_policy_config.rb, em torno da política padrão vinculada. Revise como o padrão existente sameorigin de X-Frame-Options está configurado e considere a interação indicada com frame-ancestors. A tarefa estará concluída quando for resolvido se o padrão deve incluir frame-ancestors self e a decisão for implementada sem deixar os dois controles de framing enganosamente inconsistentes.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- ruby
- Domínio
- security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Estagnada
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 38/100