matrix-org / matrix-org/matrix-spec

Add `X-Content-Security-Policy: sandbox` recommendation for the content repository

Open
#866 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

clarification enhancement
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

This is a non-standard CSP-like header supported by IE11 which only supports the `sandbox` directive. This is enough to disable script execution however and can therefore mitigate the problem of XSS in the content repository for users still using IE11.

C.f. Synapse PR: https://github.com/matrix-org/synapse/pull/10468

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the content repository's existing security guidance and CSP recommendations, then compare the referenced Synapse PR. Add the IE11-specific sandbox recommendation and verify that the documentation clearly explains its XSS-mitigation purpose and limitation.

Written by the indexing model from the issue text.

Assessment

Tech stack
html
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
40/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.