Uploaded image for project: 'OpenShift Console'
  1. OpenShift Console
  2. CONSOLE-4263

Initial Content Security Policy implementation for Console

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • HAC Infra OCP - Sprint 260

      This story follows up on spike https://issues.redhat.com/browse/CONSOLE-4170

      The aim of this story is to add initial CSP implementation for Console web application that will use Content-Security-Policy-Report-Only HTTP header to report on CSP violations.

      CSP violations should be handled directly by Console code via custom SecurityPolicyViolationEvent handler, which logs the relevant CSP violation data to browser console.

      AC:

      • Console HTML index page must be served with CSP report-only response header
      • Running dynamic demo plugin in Console must not trigger any CSP violations
      • CSP violations must be logged to browser console
      • dynamic plugins README should contain a section that describes CSP usage in Console

            vszocs@redhat.com Vojtech Szocs
            jhadvig@redhat.com Jakub Hadvig
            YaDan Pei YaDan Pei
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: