github / github/secure_headers

Set default `frame-ancestors` on default Content-Security-Policy

Aberta
#532 1 comentário 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
Ruby
Estrelas
3.2k
Forks
253
Merge médio
19h 11min
PRs com merge (30d)
1

Descrição

We should consider setting a default `frame-ancestors` directive for the Content Security Policy. The [`frame-ancestors`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors) directive is the new iteration of the X-Frame-Options header, and as such setting a directive in both spots might be prudent.

https://github.com/github/secure_headers/blob/b134eef07d3741b4bd0769b863961b41af5df57d/lib/secure_headers/headers/content_security_policy_config.rb#L97

Since our default XFO policy is `sameorigin`, if we decide to take upon this task, we should set the default `frame-ancestors` value to be `self`.

Some counterpoints: setting both the `X-Frame-Options` and the `frame-ancestors` directive will cause the XFO header to be overriden by the frame-ancestors directive. This means that if a user is trying to change some framing functionality, and only changes the XFO header, they might be confused as to why the functionality didn't actually change.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece por lib/secure_headers/headers/content_security_policy_config.rb, em torno da política padrão vinculada. Revise como o padrão existente sameorigin de X-Frame-Options está configurado e considere a interação indicada com frame-ancestors. A tarefa estará concluída quando for resolvido se o padrão deve incluir frame-ancestors self e a decisão for implementada sem deixar os dois controles de framing enganosamente inconsistentes.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
ruby
Domínio
security
Tipo de issue
Funcionalidade
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
38/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.